Carbanak+FIN7
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
19.B.5
|
|
|
|
|
A General detection named "behavioral.win.application_shimming.a" (Low ) was generated when sdbinst.exe installed sdbE376.tmp shim database.
[1]
|
|
A Technique detection named "Application Shimming" (Medium) was generated when sdbinst.exe installed sdbE376.tmp shim database.
[1]
[2]
|
|
20.A.1
|
|
Telemetry
(Configuration Change (Data Sources))
|
|
Technique
(Configuration Change (Detection Logic), Configuration Change (Data Sources))
|
A Technique detection named "Application Shimming" (Medium) was generated when AccountingIQ.exe queried HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\.
[1]
[2]
[3]
|
|
sdbinst.exe installs sdbE376.tmp shim
[1]
sdbinst.exe installs sdbE376.tmp shim
[1]
sdbinst.exe installs sdbE376.tmp shim
-
Process Monitoring
-
Windows Registry
[1]
[2]
AccountingIQ.exe queries HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\ and loads dll329.dll
-
Windows Registry
-
Process Monitoring
-
Increased collection of Registry activity
[1]
AccountingIQ.exe queries HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\ and loads dll329.dll
-
Windows Registry
-
Process Monitoring
-
Increased collection of Registry activity
[1]
[2]
[3]