indicatorfilename
C:\windows\system32\config\red.dll
- First seen
- 2026-05-13
- Last seen
- 2026-05-13
- Sightings
- 1
Posts referencing this indicator
- Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape
Malicious DLL executed via scheduled task for LIONSHARE tunneler persistence.