Tags:
adware backdoor defense_evasion discovery execution persistence privilege_escalation ransomware rat revoked_codesign spyware trojan
Uses Volume Shadow Copy service COM API
Uses Task Scheduler COM API
Suspicious use of WriteProcessMemory
Suspicious use of SetWindowsHookEx
Suspicious use of FindShellTrayWindow
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: EnumeratesProcesses
Modifies system certificate store
Modifies data under HKEY_USERS
Modifies Internet Explorer settings
Checks processor information in registry
Checks SCSI registry key(s)
System Location Discovery: System Language Discovery
Executes a command shell one-liner
Enumerates physical storage devices
Drops file in Windows directory
Drops file in Program Files directory
Drops file in System32 directory
Boot or Logon Autostart Execution: Authentication Package
Enumerates connected drives
Command and Scripting Interpreter: PowerShell
Checks installed software on the system
Adds Run key to start application
Event Triggered Execution: Component Object Model Hijacking
ConnectWise ScreenConnect remote access tool
Checks computer location settings
Signed with revoked ConnectWise certificate
Sets service image path in registry
Manipulates Digital Signatures
Boot or Logon Autostart Execution: Port Monitors
Badlisted process makes network request
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.