Configuring a Windows Domain to Dynamically Analyze an Obfuscated Lateral Movement Tool | Mandiant
Common Information
Type Value
UUID 1814c23e-6d9c-412e-8ac9-a6f98fa03308
Fingerprint bc10d9994daa07cd
Analysis status DONE
Considered CTI value 0
Text language
Published July 7, 2020, midnight
Added to db Nov. 9, 2023, 12:24 a.m.
Last updated Nov. 17, 2024, 6:54 p.m.
Headline Configuring a Windows Domain to Dynamically Analyze an Obfuscated Lateral Movement Tool
Title Configuring a Windows Domain to Dynamically Analyze an Obfuscated Lateral Movement Tool | Mandiant
Detected Hints/Tags/Attributes 46/1/7
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 330 Threat Intelligence https://www.mandiant.com/resources/blog/rss.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details File 24
evil.exe
Details File 24
c:\windows\system32\calc.exe
Details File 85
log.txt
Details File 1
dumpedswaqp.exe
Details File 249
schtasks.exe
Details File 1
hostnames.txt
Details File 1
c:\windows\swaqp.exe