Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Problem: T1486 Atomic Test #10 - Akira Ransomware drop Files with .akira Extension and Ransomnote --> Script issue #2967

Open
SirStephanikus opened this issue Oct 28, 2024 · 4 comments

Comments

@SirStephanikus
Copy link

What did you do?

Invoke-AtomicTest T1486 -TestNumbers 10 -CheckPrereqs

CheckPrereq's for: T1486-10 Akira Ransomware drop Files with .akira Extension and Ransomnote
Prerequisites met: T1486-10 Akira Ransomware drop Files with .akira Extension and Ransomnote 
Invoke-AtomicTest T1486 -TestNumbers 10

Executing test: T1486-10 Akira Ransomware drop Files with .akira Extension and Ransomnote
The string is missing the terminator: ".
    + CategoryInfo          : ParserError: (:) [], ParentContainsErrorRecordException
    + FullyQualifiedErrorId : TerminatorExpectedAtEndOfString
Exit code: 1

What did you expect to happen?

Dropping 100 files with random content and .akira File Extension and the Akira Ransomnote to c:\

What happened instead?

The string is missing the terminator: ".
    + CategoryInfo          : ParserError: (:) [], ParentContainsErrorRecordException
    + FullyQualifiedErrorId : TerminatorExpectedAtEndOfString

Your Environment

Windows Server 2022 Standard, as an AD-DC. Run with privileged user.

@SirStephanikus
Copy link
Author

Invoke-AtomicTest T1486 -TestNumbers 10 -ShowDetails

Give no hint if there is some kind of user interaction needed, so I assume it's a fire & forget atomic.

Copy link

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@github-actions github-actions bot added the Stale label Nov 28, 2024
@cyberbuff cyberbuff removed the Stale label Dec 3, 2024
Copy link

github-actions bot commented Jan 3, 2025

This issue is stale because it has been open 30 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@github-actions github-actions bot added the Stale label Jan 3, 2025
@SirStephanikus
Copy link
Author

Comment due to stale status

@github-actions github-actions bot removed the Stale label Jan 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants