ACME Anvils:
Final Report
(Recent Breach Slides)
Martian SOC Team:
Elez Topuzovic , Myra Rafalovich, Timothy Khoury
Ulrick Pimentel, and Taylor King
4/25/2021
Overview of Recent Breach
Timeline of Breach: December 2017
Dec 12th
Exploitation & Installation
Initial Entry
Dec 13th
Command and Control
MITM Attack
3 days
Dec 14th
Action on the Objective
Malware Installation
Azure Data Exfiltration
through
Dec 17th
Reconnaissance & Exploitation
Network Scanning
Known Vulnerabilities
7 days
Dec 19th
Installation &
Command and Control
Remote Access Trojan
Dec 26th
Action on the Objective
ACME Data Exfiltration
First Chain
Second Chain
Cyber Kill Chain Analysis
Recent Breach: First Chain of Events
Recent Breach: Second Chain of Events