Improved Adwind RAT rule

This commit is contained in:
Florian Roth 2017-11-09 18:53:46 +01:00
parent b558f5914e
commit 57d56dddb7

View File

@ -9,11 +9,6 @@ reference:
author: Florian Roth
date: 2017/11/09
detection:
selection:
# Could be %AppData%\Oracle\javaw.exe
# or %AppData%\Oracle\bin\javaw.exe
# %AppData% expands to ..\AppData\Roaming\
CommandLine: '*\AppData\Roaming\Oracle*\javaw.exe *'
condition: selection
falsepositives:
- 'Unknown'
@ -25,6 +20,15 @@ logsource:
detection:
selection:
EventID: 1
Image: '*\AppData\Roaming\Oracle*\javaw.exe'
---
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 11
TargetFileName: '*\AppData\Roaming\Oracle*\javaw.exe'
---
logsource:
product: windows
@ -33,3 +37,4 @@ logsource:
detection:
selection:
EventID: 4688
CommandLine: '*\AppData\Roaming\Oracle*\javaw.exe *'