Proof of Concept :: Living of the Land Binaries
Tags
Common Information
Type | Value |
---|---|
UUID | b7698648-e580-4407-beb9-dbcb87031a19 |
Fingerprint | 8ccd9bd327b67310 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | April 21, 2023, 11:46 a.m. |
Added to db | April 21, 2023, 2:18 p.m. |
Last updated | Nov. 17, 2024, 6:55 p.m. |
Headline | Proof of Concept :: Living of the Land Binaries |
Title | Proof of Concept :: Living of the Land Binaries |
Detected Hints/Tags/Attributes | 33/1/20 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 167 | ✔ | Cybersecurity on Medium | https://medium.com/feed/tag/cybersecurity | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | ground-zero-storage.s3.ap-south-1.amazonaws.com |
|
Details | Domain | 207 | learn.microsoft.com |
|
Details | Domain | 1 | dmcxblue.gitbook.io |
|
Details | File | 1 | poc.bat |
|
Details | File | 1 | running_process.txt |
|
Details | File | 1018 | rundll32.exe |
|
Details | File | 63 | bitsadmin.exe |
|
Details | File | 226 | certutil.exe |
|
Details | File | 1 | c:\users\administrator\desktop\poc_encoded_payload c:\users\administrator\desktop\poc_payload.ps1 |
|
Details | File | 1 | poc_payload.ps1 |
|
Details | File | 185 | shell32.dll |
|
Details | File | 1208 | powershell.exe |
|
Details | File | 1 | c:\users\administrator\desktop\poc_payload.ps1 |
|
Details | File | 1 | c:\users\administrator\desktop\running_process.txt |
|
Details | MITRE ATT&CK Techniques | 492 | T1105 |
|
Details | MITRE ATT&CK Techniques | 504 | T1140 |
|
Details | MITRE ATT&CK Techniques | 119 | T1218.011 |
|
Details | Url | 1 | https://ground-zero-storage.s3.ap-south-1.amazonaws.com/poc_encoded_payload |
|
Details | Url | 3 | https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil |
|
Details | Url | 1 | https://dmcxblue.gitbook.io/red-team-notes/execution/untitled |