Carbanak+FIN7
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
19.B.5
|
|
|
A Technique detection named "Installed a custom Shim database using Sdbinst.exe" (Yellow) was generated when sdbinst.exe installed sdbE376.tmp shim database.
[1]
|
|
A Technique detection named "Dropped new sdb file inside custom Shim folder" (Yellow) was generated when sdbE376.tmp shim database was created.
[1]
[2]
|
|
A Technique detection named "Application Compatibility Database installer executed on system" (Yellow) was generated when sdbinst.exe was executed.
[1]
[2]
|
|
A Technique detection named "Added or modified a custom Shim database" (Yellow) was generated when sdbE376.tmp shim database was created.
[1]
[2]
|
|
|
|
A Technique detection named "Executed Application Compatibility Database tool from PowerShell" (Yellow) was generated when sdbinst.exe was executed via PowerShell.
[1]
|
|
20.A.1
|
|
|
Minimum detection criteria was not met for this procedure.
|
|
sdbinst.exe installs sdbE376.tmp shim
[1]
sdbinst.exe installs sdbE376.tmp shim
-
File Monitoring
-
Process Monitoring
[1]
[2]
sdbinst.exe installs sdbE376.tmp shim
[1]
[2]
sdbinst.exe installs sdbE376.tmp shim
[1]
[2]
sdbinst.exe installs sdbE376.tmp shim
-
Process Monitoring
-
Windows Registry
[1]
[2]
sdbinst.exe installs sdbE376.tmp shim
[1]
AccountingIQ.exe queries HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\ and loads dll329.dll
APT29
|
The subtechnique was not in scope.
|
APT3
|
The subtechnique was not in scope.
|