Content Injection
Key Points:
Detection
File Creation
An attempt was made to access an object.
Subject:
Security ID: SYSTEM
Account Name: WIN-SERVER$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Name: C:\Users\user\AppData\Local\Temp\malicious.exe
Object Type: File
Process Information:
Process ID: 0x1f4
Process Name: C:\Windows\System32\cmd.exe
Access Request Information:
Accesses: WriteData (or AddFile)
Access Mask: 0x2Process Creation
Network Traffic Content
Mitigation
Restrict Web-Based Content
Encrypt Sensitive Information
Last updated