Carbanak+FIN7
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
5.C.3
|
|
|
A General detection named "New Service (event log)" was generated when a new service was created to execute cmd.exe.
[1]
|
|
|
|
A General detection named "New Service" was generated when a new service was created to execute cmd.exe.
[1]
[2]
|
|
16.A.6
|
|
|
|
|
A General detection named "New Service (event log)" was generated when Windows service started PAExec-{PID}-HOTELMANAGER.exe, which executes sharphollow.exe.
[1]
|
|
A General detection named "New Service" was generated when Windows service started PAExec-{PID}-HOTELMANAGER.exe, which executes sharphollow.exe.
[1]
|
|
cmd.exe spawns from a service executable in C:\Windows\
[1]
cmd.exe spawns from a service executable in C:\Windows\
[1]
[2]
cmd.exe spawns from a service executable in C:\Windows\
[1]
[2]
Windows service started PAExec-{PID}-HOTELMANAGER.exe, which executes hollow.exe
-
Process Monitoring
-
Windows Event Logs
[1]
[2]
Windows service started PAExec-{PID}-HOTELMANAGER.exe, which executes hollow.exe
[1]
Windows service started PAExec-{PID}-HOTELMANAGER.exe, which executes hollow.exe
[1]