
H Fang
@FangtasticCompletionist
0 followers0 downloads17 copies1 like66 views
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Categories
1
1
1
Platforms
1
1
MITRE Techniques
1
1
1
Detects the execution of suspicious commands via the Windows Explorer RunMRU registry key. RunMRU records commands previously entered in the 'Run' dialog box. Adversaries may use this mechanism to launch malicious scripts or tools (e.g., rundll32, powershell, pcalua) with potential arguments that include suspicious markers like '@ssl'.
RunMRU registry values containing rundll32, pcalua, powershell, or @SSL, indicating a user-pasted Run command
RunMRU registry values containing rundll32, pcalua, powershell, or @SSL, indicating a user-pasted Run command
[IOC based] Surfaces every macOS host that contacts api.ipify.org or ipinfo.io/json. These are MiniRAT's exfiltration endpoints but are also used by many legitimate tools.
