Sunturai
Threat report

thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware

https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/
Published on
thedfirreport.com
Sources in this catalogue
3

ATT&CK techniques those detections carry

  • T1003OS Credential Dumping
  • T1003.001LSASS Memory
  • T1003.002Security Account Manager
  • T1003.003NTDS
  • T1018Remote System Discovery
  • T1046Network Service Discovery
  • T1219.002Remote Desktop Software
  • T1685Disable or Modify Tools
Open the original

5 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Newly Seen Commonly Abused Network ScannerMedium
NTDS or SAM Database File CopiedHigh
Windows DISM Remove DefenderMedium
HackTool - Inveigh ExecutionCritical
HackTool - Inveigh Execution ArtefactsCritical

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice