diff --git a/Lists/WMI/suspicious_wmi_event_consummers_name_list.csv b/Lists/WMI/suspicious_wmi_event_consummers_name_list.csv index eadec9668..74d66756f 100644 --- a/Lists/WMI/suspicious_wmi_event_consummers_name_list.csv +++ b/Lists/WMI/suspicious_wmi_event_consummers_name_list.csv @@ -1,5 +1,5 @@ "wmi_consumer_name","wmi_query","wmi_consumer_destination","wmi_consumer_type","wmi_operation","metadata_tool","metadata_category","metadata_comment","metadata_link","metadata_severity","metadata_reference" -"BadActiveScriptEventConsumer",,,,"Created",,"WMIPersist","Persistence","WMI Event Subscription Persistence in C#",https://github.com/mdsecactivebreach/WMIPersistence/blob/41e49845c1337138530f852bc04662bf548ed184/WMIPersist.cs#L47C44-L47C72https://github.com/mdsecactivebreach/WMIPersistence/blob/41e49845c1337138530f852bc04662bf548ed184/WMIPersist.cs#L47C44-L47C72,"critical","https://github.com/mthcht/awesome-lists" +"BadActiveScriptEventConsumer",,,,"Created","WMIPersist","Persistence","WMI Event Subscription Persistence in C#","https://github.com/mdsecactivebreach/WMIPersistence/blob/41e49845c1337138530f852bc04662bf548ed184/WMIPersist.cs#L47C44-L47C72","critical","https://github.com/mthcht/awesome-lists" "persistence",,"*meter.exe*","Command Line","Created","Dispossessor Ransomware","Ransomware",technique used by Dispossessor ransomware group,"https://vx-underground.org/Archive/Dispossessor%20Leaks","critical","https://github.com/mthcht/awesome-lists" "SCM Event Consummer",,,,"Created","badrabbit","Ransomware","A Badrabbit ransomware variant named their evil event consummer 'SCM Event Consummer' similar to the legitimate default consummer name 'SCM Event Log Consummer'","SANS FOR508 book",critical,"https://github.com/mthcht/awesome-lists" "SCM Events Log Consummer",,,,"Created","badrabbit","Ransomware","A Badrabbit ransomware variant named their evil event consummer 'SCM Events Log Consummer' similar to the legitimate default consummer name 'SCM Event Log Consummer'","SANS FOR508 book",critical,"https://github.com/mthcht/awesome-lists"