Skip to content

Hide Navigation Hide TOC

ScreenSaver Registry Key Set (40b6e656-4e11-4c0c-8772-c1cc6dae34ce)

Detects registry key established after masqueraded .scr file execution using Rundll32 through desk.cpl

Cluster A Galaxy A Cluster B Galaxy B Level
Rundll32 - T1218.011 (045d0922-2310-4e60-b5e4-3302302cb3c5) Attack Pattern ScreenSaver Registry Key Set (40b6e656-4e11-4c0c-8772-c1cc6dae34ce) Sigma-Rules 1
System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern Rundll32 - T1218.011 (045d0922-2310-4e60-b5e4-3302302cb3c5) Attack Pattern 2