Skip to content

Commit f87b9c8

Browse files
authored
Update LOLBAS.md
1 parent ec75b63 commit f87b9c8

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

Tools/LOLBAS.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
| Tool Name | Threat Group Usage |
1010
|---|---|
1111
| attrib | BlackSuit |
12-
| BCDEdit | LockBit, Snatch, Hive, Zola, BlackCat, Cicada3301, Embargo |
12+
| BCDEdit | LockBit, Snatch, Hive, Zola, BlackCat, Cicada3301, Embargo, RansomEXX |
1313
| BITSAdmin | Black Basta, Hive, REvil, Conti, Medusa, RansomHub, Lockean* |
1414
| Curl | QWCrypt |
1515
| fsutil | Qilin |
@@ -22,6 +22,7 @@
2222
| PsExec | MAZE, BlackSuit, Royal, Black Basta, PLAY, Cuba, Rhysida, AvosLocker, BianLian, Bassterlord*, Conti, Nokoyawa, Quantum, PYSA, NetWalker, 8BASE, INC Ransom, RansomHub, EvilCorp*, Fog, Medusa, Yanluowang, Scattered Spider*, FiveHands, DarkSide, RagnarLocker, Vice Society, BlackCat, LockBit, Cicada3301, Medusa Locker, Qilin, RA World, Helldown |
2323
| Quick Assist | Black Basta |
2424
| ServiceControl (sc.exe) | Snatch, Embargo |
25+
| Wevutil | RansomEXX |
2526
| Windows Event Utility (wevtutil) | Rhysida, Hive, GoGoogle, Yanluowang, BlackCat |
2627
| WinExe | *Prophet Spider |
2728
| WMIC | MAZE, Conti, Hive, Quantum, TargetCompany, PYSA, AvosLocker, RagnarLocker, Vice Society, Rhysida, BlackCat, Cicada3301, Ghost/Cring |

0 commit comments

Comments
 (0)