216.73.217.22

File Hashes Analysis with Power BI from Data Stored in DShield SIEM

· Published 13/03/2025 09:45 · Modified 13/03/2025 11:56

Export JSON

Essential information

Published
13/03/2025 09:45
Modified
13/03/2025 11:56
Tags
2025-03-13 data analysis dshield file hashes ircbot power bi redtail siem visualization xorddos
Related entities
9 techniques (mitre), 3 malware

Description

This analysis showcases the use of to examine file hash data from a over a 60-day period. The process involved exporting data from Elastic Discover, importing it into , and creating visualizations for analysis. Key findings include the identification of an IP address (87.120.113.231) associated with malware, uploading six different files with multiple hashes. The analysis also revealed the reappearance of a previously identified Linux Trojan () from new IP addresses within the same subnet. Additionally, two strange filenames were discovered and investigated, with one identified as an through VirusTotal. This method of large dataset analysis proves valuable in uncovering potentially overlooked or lost data through retrospective examination.

External references