Carbanak+FIN7
|
The subtechnique was not in scope.
|
APT29
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
8.B.2
|
|
Telemetry
(Delayed (Processing))
|
Telemetry from automated file analysis showed python.exe was UPX packed. Detection incurred a delay based on additional data processing of python.exe to determine it was UPX packed.
[1]
|
|
A Technique detection for "Software Packing" was generated when python.exe was executed by PSExec.
[1]
|
|
python.exe payload was packed with UPX
Evidence that the file python.exe is packed
[1]
python.exe payload was packed with UPX
Evidence that the file python.exe is packed
[1]