action: global title: Advanced IP Scanner id: bef37fa2-f205-4a7b-b484-0759bfd5f86f status: experimental description: Detects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups. references: - https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/ - https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html - https://labs.f-secure.com/blog/prelude-to-ransomware-systembc - https://assets.documentcloud.org/documents/20444693/fbi-pin-egregor-ransomware-bc-01062021.pdf - https://thedfirreport.com/2021/01/18/all-that-for-a-coinminer author: '@ROxPinTeddy' date: 2020/05/12 modified: 2021/05/11 tags: - attack.discovery - attack.t1046 falsepositives: - Legitimate administrative use level: medium --- logsource: category: process_creation product: windows detection: selection: Image|contains: '\advanced_ip_scanner' condition: selection --- logsource: category: file_event product: windows detection: selection: TargetFilename|contains: '\AppData\Local\Temp\Advanced IP Scanner 2' condition: selection