diff --git a/atomics/T1218.011/T1218.011.yaml b/atomics/T1218.011/T1218.011.yaml index 2b917385..9ecbd145 100644 --- a/atomics/T1218.011/T1218.011.yaml +++ b/atomics/T1218.011/T1218.011.yaml @@ -141,6 +141,7 @@ atomic_tests: name: command_prompt - name: Execution of HTA and VBS Files using Rundll32 and URL.dll + auto_generated_guid: 22cfde89-befe-4e15-9753-47306b37a6e3 description: | IcedID uses this TTP as follows: rundll32.exe url.dll,OpenURL %PUBLIC%\index.hta diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 9f759d2d..24b5a578 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -640,3 +640,4 @@ a524ce99-86de-4db6-b4f9-e08f35a47a15 69bd4abe-8759-49a6-8d21-0f15822d6370 6afe288a-8a8b-4d33-a629-8d03ba9dad3a 24e55612-85f6-4bd6-ae74-a73d02e3441d +22cfde89-befe-4e15-9753-47306b37a6e3