Carbanak+FIN7
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
1.A.8
|
|
|
A Tactic detection named "wscript.exe started this child process" was generated when wscript.exe spawned cmd.exe.
[1]
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection was generated when wscript.exe spawned cmd.exe.
[1]
|
|
|
|
2.B.2
|
|
|
|
|
A Technique detection named "T1059 - Command-Line Interface" was generated when wscript.exe spawned cmd.exe.
[1]
|
|
3.A.1
|
|
|
A Technique detection named "Process: T1059 - Command-Line Interface" was generated when wscript.exe spawned cmd.exe.
[1]
|
|
|
|
3.B.2
|
|
|
A Technique detection named "Process: T1059 - Command-Line Interface - Windows" was generated when wscript.exe spawned cmd.exe.
[1]
|
|
|
|
4.B.6
|
|
|
A Technique detection named "Process: T1059 - Command-Line Interface" was generated when cmd.exe executed smrs.exe.
[1]
|
|
|
|
5.A.6
|
|
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "T1059 - Command-Line Interface" was generated when powershell.exe spawned cmd.exe.
[1]
|
|
5.C.5
|
|
|
|
|
A Technique detection named "T1059 - Command-Line Interface" was generated when cmd.exe spawned tiny.exe.
[1]
|
|
7.A.2
|
|
|
|
|
A Technique detection named "T1059 - Command-Line Interface" was generated when tiny.exe spawned cmd.exe.
[1]
|
|
13.A.2
|
|
|
A Technique detection named "T1059 - Command-Line Interface" was generated when Adb156.exe spawned cmd.exe.
[1]
|
|
|
|
13.B.2
|
|
|
A Technique detection named "T1059 - Command-Line Interface" was generated when Adb156.exe spawned cmd.exe.
[1]
|
|
|
|
14.A.1
|
|
|
16.A.3
|
|
Technique
(Configuration Change (Detection Logic))
|
A Technique detection named "T1059 - Command-Line Interface" was generated when powershell.exe spawned cmd.exe.
[1]
|
|
|
|
17.A.3
|
|
|
A Technique detection named "T1059 - Command-Line Interface" was generated when svchost.exe spawned cmd.exe.
[1]
|
|
|
|