Home >
Enterprise >
Participants >
Malwarebytes >
Indicator Removal on Host: File Deletion (T1070.004)
|
|
Carbanak+FIN7 |
||||||
Step | ATT&CK Pattern |
|
||||
9.B.3
|
|
APT29 |
||||||
Step | ATT&CK Pattern |
|
||||
4.B.2
|
|
|||||
4.B.3
|
|
|||||
4.B.4
|
|
|||||
9.C.1
|
|
|||||
9.C.2
|
|
|||||
9.C.3
|
|
|||||
9.C.4
|
|
Procedure
Deleted rcs.3aka3.doc on disk using SDelete
Criteria
sdelete64.exe deleting the file rcs.3aka3.doc
Footnotes
- Updates to detections and logging were enabled after the start of the evaluation, so it is identified as a Detection Configuration Change.
- Exiting event details shows correlation of detections.


Procedure
Deleted Draft.zip on disk using SDelete
Criteria
sdelete64.exe deleting the file draft.zip
Footnotes
- Exiting event details shows correlation of detections.
- Updates to detections and logging were enabled after the start of the evaluation, so it is identified as a Detection Configuration Change.


Procedure
Deleted SysinternalsSuite.zip on disk using SDelete
Criteria
sdelete64.exe deleting the file SysinternalsSuite.zip
Footnotes
- Updates to detections and logging were enabled after the start of the evaluation, so it is identified as a Detection Configuration Change.
- Exiting event details shows correlation of detections.


Procedure
Deleted working.zip (from Desktop) on disk using SDelete
Criteria
sdelete64.exe deleting the file \Desktop\working.zip
Procedure
Deleted working.zip (from AppData directory) on disk using SDelete
Criteria
sdelete64.exe deleting the file \AppData\Roaming\working.zip