Skip to content

Commit

Permalink
Update suspicious_wmi_event_consummers_name_list.csv
Browse files Browse the repository at this point in the history
  • Loading branch information
mthcht authored Jan 10, 2025
1 parent 92e3d94 commit bff8362
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion Lists/WMI/suspicious_wmi_event_consummers_name_list.csv
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
"wmi_consumer_name","wmi_query","wmi_consumer_destination","wmi_consumer_type","wmi_operation","metadata_tool","metadata_category","metadata_comment","metadata_link","metadata_severity","metadata_reference"
"BadActiveScriptEventConsumer",,,,"Created",,"WMIPersist","Persistence","WMI Event Subscription Persistence in C#",https://github.com/mdsecactivebreach/WMIPersistence/blob/41e49845c1337138530f852bc04662bf548ed184/WMIPersist.cs#L47C44-L47C72https://github.com/mdsecactivebreach/WMIPersistence/blob/41e49845c1337138530f852bc04662bf548ed184/WMIPersist.cs#L47C44-L47C72,"critical","https://github.com/mthcht/awesome-lists"
"BadActiveScriptEventConsumer",,,,"Created","WMIPersist","Persistence","WMI Event Subscription Persistence in C#","https://github.com/mdsecactivebreach/WMIPersistence/blob/41e49845c1337138530f852bc04662bf548ed184/WMIPersist.cs#L47C44-L47C72","critical","https://github.com/mthcht/awesome-lists"
"persistence",,"*meter.exe*","Command Line","Created","Dispossessor Ransomware","Ransomware",technique used by Dispossessor ransomware group,"https://vx-underground.org/Archive/Dispossessor%20Leaks","critical","https://github.com/mthcht/awesome-lists"
"SCM Event Consummer",,,,"Created","badrabbit","Ransomware","A Badrabbit ransomware variant named their evil event consummer 'SCM Event Consummer' similar to the legitimate default consummer name 'SCM Event Log Consummer'","SANS FOR508 book",critical,"https://github.com/mthcht/awesome-lists"
"SCM Events Log Consummer",,,,"Created","badrabbit","Ransomware","A Badrabbit ransomware variant named their evil event consummer 'SCM Events Log Consummer' similar to the legitimate default consummer name 'SCM Event Log Consummer'","SANS FOR508 book",critical,"https://github.com/mthcht/awesome-lists"
Expand Down

0 comments on commit bff8362

Please sign in to comment.