# Malware Analysis Report: [SAMPLE NAME / FAMILY] **Report ID:** MAR-YYYY-NNNN **Date:** YYYY-MM-DD **Classification:** TLP:______ **Analyst:** _______________ --- ## Executive Summary [3-5 sentence summary: what was analyzed, key findings, business impact, recommended actions] --- ## Sample Information | Property | Value | |----------|-------| | File Name | `` | | File Size | | | File Type | | | MD5 | `` | | SHA1 | `` | | SHA256 | `` | | ssdeep | `` | | Compilation Timestamp | | | Packer/Compiler | | | First Seen | | | VT Detection | | | Source | | --- ## Technical Findings ### 1. [SEVERITY] Finding Title **Description:** **Evidence:** **ATT&CK:** --- ### 2. [SEVERITY] Finding Title **Description:** **Evidence:** **ATT&CK:** --- ## Indicators of Compromise (IOCs) ### File Indicators | Type | Value | Context | Confidence | |------|-------|---------|------------| | | | | | ### Network Indicators | Type | Value | Context | Confidence | |------|-------|---------|------------| | | | | | ### Host Indicators | Type | Value | Context | Confidence | |------|-------|---------|------------| | | | | | --- ## MITRE ATT&CK Mapping | Technique ID | Name | Tactic | Evidence | |-------------|------|--------|----------| | | | | | --- ## Detection Rules ### YARA ```yara rule Sample_Detection { meta: description = "" author = "" date = "" reference = "" strings: condition: } ``` ### Sigma ```yaml title: status: experimental description: logsource: product: service: detection: selection: condition: selection level: tags: ``` ### Network (Snort/Suricata) ``` ``` --- ## Remediation Recommendations ### Immediate Containment 1. ### Eradication 1. ### Recovery 1. ### Prevention 1. --- ## Appendices ### Appendix A: [Title] ### Appendix B: [Title] --- *TLP:______ | MAR-YYYY-NNNN | Generated YYYY-MM-DD*