Skip to content

Hide Navigation Hide TOC

Suspicious UltraVNC Execution (871b9555-69ca-4993-99d3-35a59f9f3599)

Detects suspicious UltraVNC command line flag combination that indicate a auto reconnect upon execution, e.g. startup (as seen being used by Gamaredon threat group)

Cluster A Galaxy A Cluster B Galaxy B Level
Suspicious UltraVNC Execution (871b9555-69ca-4993-99d3-35a59f9f3599) Sigma-Rules VNC - T1021.005 (01327cde-66c4-4123-bf34-5f258d59457b) Attack Pattern 1
VNC - T1021.005 (01327cde-66c4-4123-bf34-5f258d59457b) Attack Pattern Remote Services - T1021 (54a649ff-439a-41a4-9856-8d144a2551ba) Attack Pattern 2