redcanaryco / atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.
MIT License
9.74k stars 2.79k forks source link

Update T1574.002.yaml #2881

Closed amitrrajeshwarkar closed 3 months ago

amitrrajeshwarkar commented 3 months ago

Details: Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe", which can load further executables embedded in modified KeyScramblerIE.dll file.

Testing: Tested in AtomicRunner, works fine along with Cleanup Commands. Note : The DLL error popup needs to be manually closed before cleanup.