Carbanak+FIN7
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
5.C.3
|
|
|
A Technique detection named "Service Execution - T1569.002" (Medium) was generated when services.exe spawned the service executable gTerpiCf.exe.
[1]
|
|
A General detection named "Windows Service - T1543.003" (Medium) was generated when cmd.exe spawned from a service executable in C:\Windows\. .
[1]
|
|
|
|
16.A.6
|
|
|
|
|
A Technique detection named "Service Execution" was generated when Windows service started PAExec-184-HOTELMANAGER.exe, which executed hollow.exe.
[1]
|
|
cmd.exe spawns from a service executable in C:\Windows\
[1]
cmd.exe spawns from a service executable in C:\Windows\
[1]
cmd.exe spawns from a service executable in C:\Windows\
[1]
Windows service started PAExec-{PID}-HOTELMANAGER.exe, which executes hollow.exe
[1]
[2]
Windows service started PAExec-{PID}-HOTELMANAGER.exe, which executes hollow.exe
[1]