SigmaHQ/rules/apt/apt_equationgroup_dll_u_load.yml

27 lines
734 B
YAML
Raw Normal View History

2018-03-10 08:02:01 +00:00
title: Equation Group DLL_U Load
author: Florian Roth
2018-03-10 08:02:01 +00:00
description: Detects a specific tool and export used by EquationGroup
references:
- https://github.com/adamcaudill/EquationGroupLeak/search?utf8=%E2%9C%93&q=dll_u&type=
- https://securelist.com/apt-slingshot/84312/
- https://twitter.com/cyb3rops/status/972186477512839170
2018-07-25 07:50:01 +00:00
tags:
- attack.execution
- attack.g0020
- attack.t1059
- attack.defense_evasion
- attack.t1085
2018-03-10 08:02:01 +00:00
logsource:
category: process_creation
2018-03-10 08:02:01 +00:00
product: windows
detection:
2018-03-11 00:22:04 +00:00
selection1:
Image: '*\rundll32.exe'
CommandLine: '*,dll_u'
2018-03-11 00:22:04 +00:00
selection2:
CommandLine: '* -export dll_u *'
condition: 1 of them
falsepositives:
- Unknown
level: critical