SigmaHQ/rules/apt/apt_silence_downloader_v3.yml

40 lines
1.1 KiB
YAML
Raw Normal View History

2019-12-15 22:30:42 +00:00
title: Silence.Downloader V3
id: 170901d1-de11-4de7-bccb-8fa13678d857
2019-12-15 22:30:42 +00:00
status: experimental
description: Detects Silence downloader. These commands are hardcoded into the binary.
author: Alina Stepchenkova, Roman Rezvukhin, Group-IB, oscd.community
date: 2019/11/01
modified: 2020/09/01
2019-12-15 22:30:42 +00:00
logsource:
category: process_creation
product: windows
detection:
selection_recon:
Image|endswith:
- '\tasklist.exe'
- '\qwinsta.exe'
- '\ipconfig.exe'
- '\hostname.exe'
CommandLine|contains: '>>'
CommandLine|endswith: 'temps.dat'
selection_persistence:
CommandLine|contains: '/C REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /v "WinNetworkSecurity" /t REG_SZ /d'
condition: selection_recon | near selection_persistence # requires both
2020-01-19 21:34:16 +00:00
fields:
- ComputerName
- User
- Image
- CommandLine
2019-12-15 22:30:42 +00:00
falsepositives:
- Unknown
level: high
tags:
2020-09-15 21:45:33 +00:00
- attack.persistence
- attack.t1547.001
- attack.t1060 # an old one
- attack.discovery
- attack.t1057
- attack.t1082
- attack.t1016
- attack.t1033
- attack.g0091