Skip to content

Hide Navigation Hide TOC

Suspicious Screensaver Binary File Creation (97aa2e88-555c-450d-85a6-229bcd87efb8)

Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension

Cluster A Galaxy A Cluster B Galaxy B Level
Screensaver - T1546.002 (ce4b7013-640e-48a9-b501-d0025a95f4bf) Attack Pattern Suspicious Screensaver Binary File Creation (97aa2e88-555c-450d-85a6-229bcd87efb8) Sigma-Rules 1
Event Triggered Execution - T1546 (b6301b64-ef57-4cce-bb0b-77026f14a8db) Attack Pattern Screensaver - T1546.002 (ce4b7013-640e-48a9-b501-d0025a95f4bf) Attack Pattern 2