Proof of Concept :: Living of the Land Binaries
Common Information
Type Value
UUID b7698648-e580-4407-beb9-dbcb87031a19
Fingerprint 8ccd9bd327b67310
Analysis status DONE
Considered CTI value 2
Text language
Published April 21, 2023, 11:46 a.m.
Added to db April 21, 2023, 2:18 p.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline Proof of Concept :: Living of the Land Binaries
Title Proof of Concept :: Living of the Land Binaries
Detected Hints/Tags/Attributes 33/1/20
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 167 Cybersecurity on Medium https://medium.com/feed/tag/cybersecurity 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 1
ground-zero-storage.s3.ap-south-1.amazonaws.com
Details Domain 207
learn.microsoft.com
Details Domain 1
dmcxblue.gitbook.io
Details File 1
poc.bat
Details File 1
running_process.txt
Details File 1018
rundll32.exe
Details File 63
bitsadmin.exe
Details File 226
certutil.exe
Details File 1
c:\users\administrator\desktop\poc_encoded_payload c:\users\administrator\desktop\poc_payload.ps1
Details File 1
poc_payload.ps1
Details File 185
shell32.dll
Details File 1208
powershell.exe
Details File 1
c:\users\administrator\desktop\poc_payload.ps1
Details File 1
c:\users\administrator\desktop\running_process.txt
Details MITRE ATT&CK Techniques 492
T1105
Details MITRE ATT&CK Techniques 504
T1140
Details MITRE ATT&CK Techniques 119
T1218.011
Details Url 1
https://ground-zero-storage.s3.ap-south-1.amazonaws.com/poc_encoded_payload
Details Url 3
https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil
Details Url 1
https://dmcxblue.gitbook.io/red-team-notes/execution/untitled