mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
275c8feec3
* New malware examples (#103) * fix typos * add new Use in Malware entries to behaviors * new corpus entries * remove extraneous ref * restore original IDs * fix typos * Update registry.md (#101) Update C0036.001 per "Registry micro-behavior" Discussion. * Update registry.md (#102) Update C0036.001 per "Registry micro-behavior" Discussion. * correct modified date * fix PR comments on formatting * Editing references (#104) --------- Co-authored-by: Desiree Beck <dbeck@mitre.org>
1.2 KiB
1.2 KiB
| ID | E1569 |
| Objective(s) | Execution |
| Related ATT&CK Techniques | System Services (T1569) |
| Version | 2.0 |
| Created | 8 November 2021 |
| Last Modified | 31 October 2022 |
System Services
Malware may abuse system services or daemons to execute.
See ATT&CK: System Services (T1569).
Methods
| Name | ID | Description |
|---|---|---|
| MSDTC | E1569.m01 | The Distributed Transaction Coordinator (MSDTC) coordinates transaction across multiple resource managers (databases, message queues and file systems). This legitimate Microsoft service is part of Windows 2000 and later and can be used to import and load DLLs. Malware may abuse MSDTC to import and load DLLs.[1] |
References
[1] https://cyware.com/news/catb-ransomware-exploits-msdtc-service-to-steal-data-3bb46fc0