HowTo: Detecting Persistence Mechanisms
Common Information
Type Value
UUID 171cbe38-6648-4c0a-a39f-49d2f6cd07af
Fingerprint 375459d748e51f89
Analysis status DONE
Considered CTI value 0
Text language
Published July 15, 2013, 11:01 a.m.
Added to db Jan. 19, 2023, 12:07 a.m.
Last updated Nov. 17, 2024, 6:49 p.m.
Headline Windows Incident Response
Title HowTo: Detecting Persistence Mechanisms
Detected Hints/Tags/Attributes 59/1/5
Attributes
Details Type #Events CTI Value
Details File 6
c:\windows\system32\imm32.dll
Details File 12
ntshrui.dll
Details File 1
c:\windows\system32\some_dll.dll
Details File 1260
explorer.exe
Details File 16
imm32.dll