Files
MBCProject-mbc-markdown/execution/system-services.md
T
Ryan Xu f7d92d59fa Staging (#124)
- Updating capa detection in behaviors
- Newsletter
- Conti malware
- pafish faq
2023-09-20 15:57:32 -04:00

1.2 KiB

ID E1569
Objective(s) Execution
Related ATT&CK Techniques System Services (T1569)
Version 2.0
Created 8 November 2021
Last Modified 12 June 2023

System Services

Malware may abuse system services or daemons to execute.

See ATT&CK: System Services (T1569).

Methods

Name ID Description
MSDTC E1569.m01 The Distributed Transaction Coordinator (MSDTC) coordinates transaction across multiple resource managers (databases, message queues and file systems). This legitimate Microsoft service is part of Windows 2000 and later and can be used to import and load DLLs. Malware may abuse MSDTC to import and load DLLs.[1]

References

[1] https://cyware.com/news/catb-ransomware-exploits-msdtc-service-to-steal-data-3bb46fc0