General

  • Target

    PrismLauncher-Windows-MSVC-Setup-8.3 (1).exe

  • Size

    18.1MB

  • Sample

    240622-x5v7kavhjm

  • MD5

    d03e25e914d36f2375c28ed0ee277432

  • SHA1

    fc9b209ac8272e91c81df60cc97c4cbcada6f149

  • SHA256

    c2fc663f23d734380807de7b7f5897376cdc1e3cd547d51ab515a3a4e72ab073

  • SHA512

    f94b595188b2b1a8f6bf5f30a0d1d8fb1dd57e7e66519a77e9dd6c79ad606a585b134fb6b9a8efb301afe91e117b4d8b7551133a6d658e0eb399ea18e191d6c3

  • SSDEEP

    393216:CNnQQvlCZznocxWjGHuoeoKn/ZwtI4Np+uH5Xw7nxQPY1DrnQDtZqw2MQjgXjc:CNnQQvMBocxyGOo/Ixb4v+uZjqPQDtZa

Malware Config

Targets

    • Target

      PrismLauncher-Windows-MSVC-Setup-8.3 (1).exe

    • Size

      18.1MB

    • MD5

      d03e25e914d36f2375c28ed0ee277432

    • SHA1

      fc9b209ac8272e91c81df60cc97c4cbcada6f149

    • SHA256

      c2fc663f23d734380807de7b7f5897376cdc1e3cd547d51ab515a3a4e72ab073

    • SHA512

      f94b595188b2b1a8f6bf5f30a0d1d8fb1dd57e7e66519a77e9dd6c79ad606a585b134fb6b9a8efb301afe91e117b4d8b7551133a6d658e0eb399ea18e191d6c3

    • SSDEEP

      393216:CNnQQvlCZznocxWjGHuoeoKn/ZwtI4Np+uH5Xw7nxQPY1DrnQDtZqw2MQjgXjc:CNnQQvMBocxyGOo/Ixb4v+uZjqPQDtZa

    • Checks computer location settings

      Looks up country code configured in the registry, likely geofence.

    • Executes dropped EXE

    • Loads dropped DLL

    • Modifies file permissions

    • Blocklisted process makes network request

    • Checks installed software on the system

      Looks up Uninstall key entries in the registry to enumerate software on the system.

    • Enumerates connected drives

      Attempts to read the root path of hard drives other than the default C: drive.

    • Detected potential entity reuse from brand microsoft.

    • Drops file in System32 directory

    • Target

      $PLUGINSDIR/System.dll

    • Size

      12KB

    • MD5

      4add245d4ba34b04f213409bfe504c07

    • SHA1

      ef756d6581d70e87d58cc4982e3f4d18e0ea5b09

    • SHA256

      9111099efe9d5c9b391dc132b2faf0a3851a760d4106d5368e30ac744eb42706

    • SHA512

      1bd260cabe5ea3cefbbc675162f30092ab157893510f45a1b571489e03ebb2903c55f64f89812754d3fe03c8f10012b8078d1261a7e73ac1f87c82f714bce03d

    • SSDEEP

      192:VjHcQ0qWTlt7wi5Aj/lM0sEWD/wtYbBjpNQybC7y+XZv0QPi:B/Qlt7wiij/lMRv/9V4bvr

    Score
    3/10
    • Target

      $PLUGINSDIR/nsDialogs.dll

    • Size

      9KB

    • MD5

      1d8f01a83ddd259bc339902c1d33c8f1

    • SHA1

      9f7806af462c94c39e2ec6cc9c7ad05c44eba04e

    • SHA256

      4b7d17da290f41ebe244827cc295ce7e580da2f7e9f7cc3efc1abc6898e3c9ed

    • SHA512

      28bf647374b4b500a0f3dbced70c2b256f93940e2b39160512e6e486ac31d1d90945acecef578f61b0a501f27c7106b6ffc3deab2ec3bfb3d9af24c9449a1567

    • SSDEEP

      96:o4Ev02zUu56FcS817eTaXx85qHFcUcxSgB5PKtAtoniJninnt3DVEB3YsNqkzfFc:o4EvCu5e81785qHFcU0PuAw0uyGIFc

    Score
    3/10
    • Target

      $PLUGINSDIR/nsExec.dll

    • Size

      7KB

    • MD5

      b4579bc396ace8cafd9e825ff63fe244

    • SHA1

      32a87ed28a510e3b3c06a451d1f3d0ba9faf8d9c

    • SHA256

      01e72332362345c415a7edcb366d6a1b52be9ac6e946fb9da49785c140ba1a4b

    • SHA512

      3a76e0e259a0ca12275fed922ce6e01bdfd9e33ba85973e80101b8025ef9243f5e32461a113bbcc6aa75e40894bb5d3a42d6b21045517b6b3cf12d76b4cfa36a

    • SSDEEP

      96:JwzdzBzMDhOZZDbXf5GsWvSv1ckne94SDbYkvML1HT1fUNQaSGYuH0DQ:JTQHDb2vSuOc41ZfUNQZGdHM

    Score
    3/10
    • Target

      Qt6Core.dll

    • Size

      5.0MB

    • MD5

      6aa247295238c61db3c57d8010716335

    • SHA1

      c64372047bc51a63551ea8cb4144c06cade0fd0a

    • SHA256

      c9f58a2b6bd0496340639470c7718cc76314d56017f5aaae48ec655ad2f14385

    • SHA512

      a373858561b1acfc86924c27aec725172713eccff66f82efce6d57f837a8b08e9f8606206b8e1b1b62135ead5634ed2f1532f4360e361f74d4c22f073cb05ac5

    • SSDEEP

      49152:u2CQUPAGYdJn+5Im58kP6zNqVJLACl5D4CmV684bbTx5Hdr6Ek11RzVSGlgO2v8b:JJGA1rStYqo49KFdu9CwJsv6tjg

    Score
    1/10
    • Target

      Qt6Core5Compat.dll

    • Size

      851KB

    • MD5

      e50b9b3fa16362c86a40e6255c6b45e7

    • SHA1

      fa8ce8fd6d4415abdb67597735575dc83a8fc634

    • SHA256

      c95ab3df8dc0bfd92925b7b8b51bce859ae09008691874a5c6f5630969557564

    • SHA512

      03a8ac0ae14e8420dd9fd91bc1619d072882d152127b3f2f1c6f7e670b7c54c524490e7c84a7cd0b76e2db413439a1ca55c4e03416fd6beb47b1067c3e960cba

    • SSDEEP

      12288:xbqiBp2WMX7t4i8ZOOSD5RC940wGsPGE/4717VKIyBDPzHkSDGGJf6bfOGQyMjDu:JeWe7t43veC9UG8G7VeDPTMTfnMXh4

    Score
    1/10
    • Target

      Qt6Gui.dll

    • Size

      8.5MB

    • MD5

      7875aad0d0d426e9d1b132a35266de32

    • SHA1

      8b7656e3412ae546153d2d3df91a6ff506d64749

    • SHA256

      fc2464f62d7915ddeaebb5490bee6d60e7b42ad5a223d5812f0993c27c35be19

    • SHA512

      9fa16c5c628f2e9b242323aed4c1aa70f093cee9f341ac61640287ff9be8663658f502769e037a8409943d3c9ab826bb1c6f88532f0fbacdaea28b2353cdfba9

    • SSDEEP

      98304:xNydcIXNBZBRhOWJDzxMv6n/aSu0shezBE4:xRIhBRxJDzY6n/nu0WeB

    Score
    1/10
    • Target

      Qt6Network.dll

    • Size

      1.4MB

    • MD5

      960f50470059381c65833145036fef29

    • SHA1

      270e230bfc9248e5ecff9ea8dfbc5f1066df02ee

    • SHA256

      1071f4f88c65317401bf93a2ffb55e661adcbb84f05911879ab21a6656521a68

    • SHA512

      cb0a0d63aaae1b9646dad722759b1c53b36ed13a4231a30b054f6124bcc69e7285c5777ab6bbbb8296756d6c31fc94e735db42c5155db35274e0ec25c1406582

    • SSDEEP

      12288:DVf2kuxdwo86ZrLlGZHLcCzIOLDjl4LgtMEmASO3xMBgt2qAa:DRDuxdwUZnlGOCzQkMp/Bgt27a

    Score
    1/10
    • Target

      Qt6Svg.dll

    • Size

      377KB

    • MD5

      67a888c61e6f1dceefbde7287e80e59d

    • SHA1

      4cbd1ea71ca25a6b87c64c163d1fb3e61cdacc2f

    • SHA256

      22c48c35d9915bc89b13d2dca91c74b8531989a887faf642c795bf593e00306a

    • SHA512

      aab6f980e0b397fd7e8823370ac398d108f20a2f5c3ca052391a7c753ef77c82d94e0a37d64bc708aeb5c95d31e534faa1a6a7582d80fc285325acaec226f1e9

    • SSDEEP

      6144:NrCsrknzH2m/rXsu5ea8r/c55qah10+9F+Yw5UibIyj:Nr7r+TTD8r/oqaJoIy

    Score
    1/10
    • Target

      Qt6Widgets.dll

    • Size

      6.2MB

    • MD5

      34abb42b63e71b09b72b48cf5b1dba53

    • SHA1

      9f3111aab57a5f28a4ce9bf82ea208fa3eadb9a6

    • SHA256

      c71e65b882a84f47114590784a256f14ba19202ec30b218ce4841b2c7256060b

    • SHA512

      06acab5a04a5d3e6834ddc95229758d4adc7a7f0ef003c80e8d59a8241e295b196aceacce20c88879e1676405a2538d032ec6ac543258538e686878fb29f77f1

    • SSDEEP

      98304:RCOQZE8fxqbA2SwuevAGcYYaCsGf1e5A64N9m3JL:RCOQa8fxqsKuevAGcXacIW4

    Score
    1/10
    • Target

      Qt6Xml.dll

    • Size

      151KB

    • MD5

      7fcfa82dd4a01915622c14931cc585dd

    • SHA1

      079736f39ed5791df528fed5a12456285bfa1f18

    • SHA256

      8b772f5f227b266c47655d02843bf51be6c50729acc28db7dced488d62f7ed4f

    • SHA512

      caf98eecb1c57789b91dbef88c3f908f0652d29d93ae335526987a47f791d565e67e25ee4643abd006a39b2d9533449672c2c21df23cc61d77032c3cd01d6f39

    • SSDEEP

      1536:mwnpe/AQ7BlrQR2d4KQfKlxQYCfmh2DGFd7ZsSCLVFEIK0qwxDqyDzbYTOj9AIKG:xIAQ9YQ47KsYAJGFNHCTRqipzvyP7Kvt

    Score
    1/10
    • Target

      iconengines/qsvgicon.dll

    • Size

      69KB

    • MD5

      b57d0218475b81560454e6c0a1a6d9c8

    • SHA1

      21206763e7121d4792bbf24075c6f6e27c2c11db

    • SHA256

      8ab3b526b35a0dec08b4042da70f942b3b5f4d413ad4035c691f972b2008778e

    • SHA512

      83464c21073edddcd77dc0978257bf13554ef01825672b60081d9d4ee5caefffe9ed6fbefda0bc7bdc413925b9265981a994195700190cd81cf6b1c93810e891

    • SSDEEP

      1536:UzibTbDQn6wcma+mHKT6IQubV5awlhBlfbnCMmbizDRT9WcwgKxngep6v:UObTzq6IQubV5awlhBlfbnCMLzDRHZKe

    Score
    1/10
    • Target

      imageformats/qgif.dll

    • Size

      47KB

    • MD5

      000b3771b3dcf0d7eb72750edd80a192

    • SHA1

      35506ee878b8ad21dbd35876baaf586c30152b71

    • SHA256

      6ff0b57822dae5132e1640afe4f8fd6b75e21cf3f1eae53d70373c25a5506581

    • SHA512

      4472089f5524172fcfd8d2f8acbf67a3f22b08f788b52d8f42d2736d050cecb87215a9b8d706baca12d5916d3ff79bf57420766746c2484981d679239b3f2924

    • SSDEEP

      768:/ONXrIbWKNNy/Qq0rvEx2eVG5bvUbBy+oBS/oxgKxnVbGYJlWLNBf:WJrIb9KQOVG5eBy+oBSQxgKxngekf

    Score
    1/10
    • Target

      imageformats/qicns.dll

    • Size

      55KB

    • MD5

      b8466ebadaac59acc5fffb674fcc81c0

    • SHA1

      d40349f19c85405fac6d027008a47a51de9e82f2

    • SHA256

      79b31f4de8f3d4ae02d1115e4ec384aad568b4fba8631b5a01a578c42748df19

    • SHA512

      ddecf05443bc19b95bbb654b7ea9417a26f37b9c8a293d16fcd6e817eb984baf0497e183acfe91096e3b1f6367e827fa3833b0a90fb964671af014c78e9c16d4

    • SSDEEP

      1536:YjQEXCukdHgnHhuS+JJXGAjTaO5HjzbgKxngec9r:YsEqgP+JraO5Hjz0KI1

    Score
    1/10
    • Target

      imageformats/qico.dll

    • Size

      46KB

    • MD5

      c64789dba4e2aa3bddf17bfa89e7ab59

    • SHA1

      d5914f9eede38dda3e16c4299fce8016799b28d3

    • SHA256

      bceee911a3ffc1ed7b09a9d79374053fa813a04a22c40b0a4984b845582e3e8f

    • SHA512

      31e5a009284867a591ac9dbce92bddbd8b914133bb03b327984edfc4c3f4329a08238b1a239e7408d8efc715ff23acfa91723720879ab8fd4a2619e948ab5683

    • SSDEEP

      768:f0hZMxD05ahDHpeNoU3LPepnzGn+J7wnZ2gKxnVbGYJloNb:cU052peN57PeRzGn+J7wZ2gKxngey

    Score
    1/10
    • Target

      imageformats/qjpeg.dll

    • Size

      552KB

    • MD5

      3aba46b716d9cb3b99efad42ed7970ee

    • SHA1

      aeabe030389dff2fec45797f3f726bc2bfbe4f8d

    • SHA256

      03ebe96116bf6e98fe967f046e62ab269ff863a3bf4dc9a817e0704b6199899a

    • SHA512

      7e750950f4d9a31f56c3a54bb363711b6326ed42ac09a21da41fef5c78c18b4ab6fc21e340f7660c8a8b8444903dc52a258207abb6b40176b5142c7091a83e7f

    • SSDEEP

      6144:BIrdnEH48pRZgGBj+3H2WR8Po8M7Kbm7/1HLh6pkUj01SwbnyEPz/cN4XA11CUBN:eRGZhkUuSeFZ6464DJvAT

    Score
    1/10
    • Target

      imageformats/qsvg.dll

    • Size

      39KB

    • MD5

      21d1279f76e64e42db06c9e27776d3cf

    • SHA1

      6f24d575f44d43abf8a2ee2d9a4b7dcee1537e9b

    • SHA256

      8878473e57bdc0a754a6df4fcdc5c13ed5500adbb0a057f73b21674514adcfc6

    • SHA512

      1beb7d24375fe6bc6dfccf564836a77bb68679d6f7b81364476ac346e6a0fa48d1b6782f101823c51550c600940c78fee79567eca248fb3b782d7bfead7d7141

    • SSDEEP

      768:WjnLIUmgd9o0+iWCKmrDqVZKgKxnVbGYJllsDNMb8:7Umgd9FLWCKmrDqVZKgKxngerb8

    Score
    1/10
    • Target

      imageformats/qwbmp.dll

    • Size

      37KB

    • MD5

      50854ae793a75bdbe0fcab1867b6f932

    • SHA1

      91f15c56945d08d7ad54339c68e7318a7fa653b4

    • SHA256

      92283f9f9588a12c630848c0949421dcb9aa33cd6545ff1e3e480ce3d7e7e617

    • SHA512

      437a7626dfa90038800068e385c5bd8515f7394366532769defd7a7992593f5051314a1c77ccb9b87d47c304dfc9be62e39444250651f4c8cab9052c65ded14f

    • SSDEEP

      768:DptuZOmR3P+NX2JE7lTuWOrHDygKxnVbGYJlTPNAt:8OGP6X2JE7lTuWOrHDygKxnge2t

    Score
    1/10
    • Target

      imageformats/qwebp.dll

    • Size

      527KB

    • MD5

      cee0dddffeb26ea50268414c28e656c3

    • SHA1

      67f5c820e62c4e8bd8596f70fbf316496477df2e

    • SHA256

      d3a1cdcb53b229040a065534465e1db27c3347b29d80417c22ccf8b7fd65a4e0

    • SHA512

      9847e491527a81f67e6e32bb0cb27fea1785e227bd8fca3b35b1dc451cce647d9e9df23abdfeefba064f98134c3a2e3a584481625d584576aeba6ce293037847

    • SSDEEP

      12288:9zaweeWDsi1cALrLrLrLwc/EMOTmUZxx2E9QxDRTr3:5aZpqALrLrLrLwc/EMOTmex2EWr3

    Score
    1/10
    • Target

      jars/JavaCheck.jar

    • Size

      1KB

    • MD5

      f62d3996b12c029c3a3bad80b70aa483

    • SHA1

      5707a289a2487602e02376378deb63e75de2e83a

    • SHA256

      885bb0c56f0657fda08ad5d46043db424e3ff9965757039b30e1a656751c5e3b

    • SHA512

      8b952e47b1e5cc061157412771b2d4ecb3215246e43ba12bb3fd83da6f6957c4b722cc6bf77c5bd067a4b6f50f5a26a2b6542f04e7b1cc02d78b39c440d8d949

    Score
    7/10
    • Target

      jars/NewLaunch.jar

    • Size

      13KB

    • MD5

      b7c74c310eefc0b4a85cc8c8f4e38216

    • SHA1

      a482ba756bd06d45e34e17f71ff570be83a203ad

    • SHA256

      d74add64df7329bc0bb16491117fb17c65676ed80df1ab75166d13381ff85bba

    • SHA512

      e2d33dc6730a913a3126a9fe41a55b93623e8f263c6af290f96e392f2b00683663a38d729696b772f0fcfbbc61c0f36b5e5ac1ff5a441ce16b19078ac2509a2d

    • SSDEEP

      192:TIFF8voDNpApTranKql6tnlTobcjXvXR0Xy+jjquGBeGnhECnsE:cFF8QJpARrHFVDBeGUE

    Score
    7/10
    • Target

      jars/NewLaunchLegacy.jar

    • Size

      23KB

    • MD5

      87cd4488ae5f1152e623857a4bf10604

    • SHA1

      375877de65e4dadd240dd9690c01bb946fdaf082

    • SHA256

      b2c4d10eb36cddac20b937f1d08a7f12baafc592ca626e8384b121fd10c200b2

    • SHA512

      12815d2fa811bdc5946a725f6ed315a36dad55c2321d95ca667fff8df3b41493cc5d2039253064d684e9b8bf46fc3c26006e29d7d90f46285217c037e9239ea7

    • SSDEEP

      384:KIVL46DQUfYeONPlSEaNp1jM8Buc6gd9rMgTbaD/8SOWlKxH:KIV+NlCp1jLGy9QgTuD/8SO2Kh

    Score
    7/10
    • Target

      platforms/qdirect2d.dll

    • Size

      939KB

    • MD5

      a883645fd99ed6b7d6398e1bbc5028d0

    • SHA1

      ab0afcb2d58df52f402c0a2a81bf3f769fea15fa

    • SHA256

      9386b1af2adbf8972801723f7d13f394d96001e979f06dd0695622a6a3ad63a8

    • SHA512

      d70aafb4cbc0c2f2a8fc16e3560248f867908548c7b970d827ee9ad8c7342502dcf77a7b442a06a547dda6bdc6f3673dde5f909242327161fe1fdb272575ee3e

    • SSDEEP

      24576:QxUvGQVkx2CU1pZIEssh6meUMW90X7hNo8FEJxGH:QxUdVkx2CU1TI5shKW90X7ro8sx8

    Score
    1/10
    • Target

      platforms/qwindows.dll

    • Size

      869KB

    • MD5

      6031ccd3785bafba8556008cbc058dfd

    • SHA1

      885147d02060dab7b0a124865c8116a478297ce0

    • SHA256

      2bdc29b85bd94170f97aadb1cd447eefe7a3ddf7950c535c81a9ef63e17d1ddc

    • SHA512

      b35c58cddc461c0160ee223fddcc181d8e6c21b5713fd8d216334b69f6ab1e4c12f4da1d377fd5b718db2c723ab20b673ab89190a3acc88d3cab03ff23bfd23d

    • SSDEEP

      12288:a43KXCSGnR4CZN6RMCojCXX/4wVlfc6TjxWFsiHxmZ:a43KDGnR4CZN6RMCojCBXk6TjxoRmZ

    Score
    1/10
    • Target

      prismlauncher.exe

    • Size

      4.0MB

    • MD5

      08dfb736fe2dac4d9e7a5686141693bb

    • SHA1

      de0139b7b73102df01773d5b5bbcc99aea3914bf

    • SHA256

      5826b658f4b100f7097f3cd0ac5a91d7e3f4a79aca7889a7400bd62ad487dcdf

    • SHA512

      267fd54c119fba49dac6a5ca5bf46816c98219175b936c6ed5c04f27856386b9792a46ed62bf24551f2d36423fb6eafeb6a96dec87ec5aa886a73ae40d56bd7d

    • SSDEEP

      49152:3xhrgs4yDxA1ZW1HlFRSVxXcA9K48ozbFnjCgfwL9sYeZ0T4wGVTXamqvDJZoPUh:TdghH1XBqcsRS+w/

    Score
    1/10
    • Target

      prismlauncher_filelink.exe

    • Size

      99KB

    • MD5

      a51dbbb945f1c186ed63a246e1bfb99f

    • SHA1

      63f4c34055ddada83faeaaca473eff46a33d3e3a

    • SHA256

      fb3684d93b4210090c0b40f188b1d4ea529aa1780f7458f07cc635246cff3328

    • SHA512

      283420343e2018de863527e1b5a3e5b40bf8f1096904376bc351219a0dfc3e4dbd1a73053832eb2f00fcc03c8272cbc0995dc75b433cab84146f71068131c898

    • SSDEEP

      1536:i0ha9sFevs8yFjn1i+4+zwNozxYFXD6NYIHn/s3+v9CJsMm3IHxHRg:iOa9sFLFjnE+NTxYFXSH03+vmsfYRxg

    Score
    1/10
    • Target

      prismlauncher_updater.exe

    • Size

      719KB

    • MD5

      5ba603e7a247e38018d48906ec8585e6

    • SHA1

      5c40b2634b60573a69c4eb4ad2a15361e0b4a850

    • SHA256

      8b5f629de662fdf2db034a5eeef1d3e3f6b59c5e6ccc2be53a66f9901d75b091

    • SHA512

      f772b5f40c4d87c0f75473fae2e917ae90fd08220aaf78c1ce09112a9d739b184891f431dd5f7390899b245b849bc153afecf33d52ecffc9d5ef4469eecf86ea

    • SSDEEP

      12288:2GYh/WY52xr9+YohC86egJ++g6TrUnOiNo+M9ztEoYkmCKHEGVz734i8rmv:HYh/F52xrUnhH6e6j1PCF8a

    Score
    1/10
    • Target

      styles/qwindowsvistastyle.dll

    • Size

      140KB

    • MD5

      cc096aea386047b0131eea248122c0d2

    • SHA1

      6251253bbc6e4460884bfc22c1dd30cec32dbac4

    • SHA256

      47a22e7958279e7668ace09849a669f7410bf8c7aed752bd6e60f23c9581cd50

    • SHA512

      4b097b86a21ac26e8849bf3908de97479b3484f28a68060c06f75515b07b8878466bce4241aae6b0c06a1b671b59b5dd115c760f08dc6d3287f1b875963d1cb1

    • SSDEEP

      3072:8zlYfzLG/ztKAYBxDwZ89kL7Cl4CpHl1uhfJWu5lzg0CJUXZmjOtkRKM:0lYf30gfDDsYUJWubzgfJUXZmjqM

    Score
    1/10
    • Target

      tls/qschannelbackend.dll

    • Size

      229KB

    • MD5

      8eca729b0b937a63aaa105c98c2647f1

    • SHA1

      9a047c46345d6f0d48ed9901bf8fbbc20d902714

    • SHA256

      f0dba9588db6f1599b0668b8b41d054e549e2b7bcdea6e5a1f36f49925d50efc

    • SHA512

      74347a89a14c8e884fd20c860940b54e32b172edeec5639ed3c4ff9db9eea2ec2281d54facdb64d71fb1e63ec462063ad844277522c0a3162a4f8b72d18a0c92

    • SSDEEP

      6144:yfGf+SYQavOpvLW9AmYaq3voiMWUcNHl+FuJrywmvVoabwaMjcSeRmWvBfp:MhqLW9AmYaq3voiMWUcNHl+FuJrywyV3

    Score
    1/10

MITRE ATT&CK Matrix ATT&CK v13

Defense Evasion

File and Directory Permissions Modification

4
T1222

Discovery

Query Registry

6
T1012

System Information Discovery

6
T1082

Peripheral Device Discovery

2
T1120

Tasks