Tag
high
advisory
Detection of Nimgrab Utility Usage
1 rule 1 TTP 2 IOCsDetection of the Nimgrab utility, a command-line tool often used for remote file downloads and potentially leveraged for stages of command-and-control operations.
pua
command-and-control
download-utility
1r
1t
2i
high
advisory
Suspicious Execution of Renamed Sysinternals Tools via Registry
1 rule 2 TTPsThis brief details a detection method for adversaries using renamed Sysinternals tools, a legitimate suite of utilities, to evade endpoint detection by triggering the `EulaAccepted` registry key creation, potentially leading to unauthorized system manipulation or data access on Windows systems.
sysinternals
evasion
registry
windows
pua
1r
2t
high
advisory
You do surprise me.exe: Unexpected Crypto-Miner in Hola Browser
3 rules 5 TTPs 4 IOCsSophos X-Ops discovered that Hola Browser version 1.251.91.0 was distributed with an undeclared crypto-mining executable, me.exe, due to a supply chain compromise, leading to resource hijacking on affected Windows systems.
Hola Browser
supply-chain-compromise
cryptomining
pua
windows
executable
3r
5t
4i