Tag
high
advisory
Suspicious Execution of Renamed Sysinternals Tools via Registry
1 rule 2 TTPsThis brief details a detection method for adversaries using renamed Sysinternals tools, a legitimate suite of utilities, to evade endpoint detection by triggering the `EulaAccepted` registry key creation, potentially leading to unauthorized system manipulation or data access on Windows systems.
sysinternals
evasion
registry
windows
pua
1r
2t
high
advisory
You do surprise me.exe: Unexpected Crypto-Miner in Hola Browser
3 rules 5 TTPs 4 IOCsSophos X-Ops discovered that Hola Browser version 1.251.91.0 was distributed with an undeclared crypto-mining executable, me.exe, due to a supply chain compromise, leading to resource hijacking on affected Windows systems.
Hola Browser
supply-chain-compromise
cryptomining
pua
windows
executable
3r
5t
4i