mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Merge pull request #757 from tliffick/master
added rule for Blue Mockingbird (cryptominer)
This commit is contained in:
commit
0afe0623af
45
rules/windows/malware/win_mal_blue_mockingbird.yml
Normal file
45
rules/windows/malware/win_mal_blue_mockingbird.yml
Normal file
@ -0,0 +1,45 @@
|
||||
action: global
|
||||
title: Blue Mockingbird
|
||||
id: c3198a27-23a0-4c2c-af19-e5328d49680e
|
||||
status: experimental
|
||||
description: Attempts to detect system changes made by Blue Mockingbird
|
||||
references:
|
||||
- https://redcanary.com/blog/blue-mockingbird-cryptominer/
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1112
|
||||
- attack.t1047
|
||||
author: Trent Liffick (@tliffick)
|
||||
date: 2020/05/14
|
||||
falsepositives:
|
||||
- unknown
|
||||
level: high
|
||||
detection:
|
||||
condition: 1 of them
|
||||
---
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
detection:
|
||||
exec_selection:
|
||||
Image|endswith: '\cmd.exe'
|
||||
CommandLine|contains|all:
|
||||
- 'sc config'
|
||||
- 'wercplsupporte.dll'
|
||||
---
|
||||
logsource:
|
||||
category: process_creation
|
||||
product: windows
|
||||
detection:
|
||||
wmic_cmd:
|
||||
Image|endswith: '\wmic.exe'
|
||||
CommandLine|endswith: 'COR_PROFILER'
|
||||
---
|
||||
logsource:
|
||||
product: windows
|
||||
service: sysmon
|
||||
detection:
|
||||
mod_reg:
|
||||
EventID: 13
|
||||
TargetObject|endswith:
|
||||
- '\CurrentControlSet\Services\wercplsupport\Parameters\ServiceDll'
|
Loading…
Reference in New Issue
Block a user