mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
f7d92d59fa
- Updating capa detection in behaviors - Newsletter - Conti malware - pafish faq
1.2 KiB
1.2 KiB
| ID | E1569 |
| Objective(s) | Execution |
| Related ATT&CK Techniques | System Services (T1569) |
| Version | 2.0 |
| Created | 8 November 2021 |
| Last Modified | 12 June 2023 |
System Services
Malware may abuse system services or daemons to execute.
See ATT&CK: System Services (T1569).
Methods
| Name | ID | Description |
|---|---|---|
| MSDTC | E1569.m01 | The Distributed Transaction Coordinator (MSDTC) coordinates transaction across multiple resource managers (databases, message queues and file systems). This legitimate Microsoft service is part of Windows 2000 and later and can be used to import and load DLLs. Malware may abuse MSDTC to import and load DLLs.[1] |
References
[1] https://cyware.com/news/catb-ransomware-exploits-msdtc-service-to-steal-data-3bb46fc0