CMSTP
Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. (Citation: Microsoft Connection Manager Oct 2009) CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections. Adversaries may supply CMSTP.exe with INF files infected with malicious commands. (Citation: Twit...
BY SOURCE
PROCEDURES (14)
Auto-extracted: 3 detections for child process
Auto-extracted: 3 detections for network connection monitoring
Auto-extracted: 2 detections for ransomware
Auto-extracted: 2 detections for suspicious
Auto-extracted: 2 detections for process creation monitoring
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for bypass
Auto-extracted: 1 detections for persist
Auto-extracted: 1 detections for registry monitoring
Auto-extracted: 1 detections for module load monitoring
Auto-extracted: 1 detections for process access monitoring
Auto-extracted: 1 detections for bypass
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for script execution monitoring