SigmaHQ/wazuh/rules/sigma_win_apt_gallium.yml
joker2013 50379800f2 123
2020-12-03 01:43:30 +03:00

44 lines
2.2 KiB
YAML

alert:
- debug
description: Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.
filter:
- query:
query_string:
query: sha1:("53a44c2396d15c3a03723fa5e5db54cafd527635" OR "9c5e496921e3bc882dc40694f1dcc3746a75db19" OR "aeb573accfd95758550cf30bf04f389a92922844" OR "79ef78a797403a4ed1a616c68e07fff868a8650a" OR "4f6f38b4cec35e895d91c052b1f5a83d665c2196" OR "1e8c2cac2e4ce7cbd33c3858eb2e24531cb8a84d" OR "e841a63e47361a572db9a7334af459ddca11347a" OR "c28f606df28a9bc8df75a4d5e5837fc5522dd34d" OR "2e94b305d6812a9f96e6781c888e48c7fb157b6b" OR "dd44133716b8a241957b912fa6a02efde3ce3025" OR "8793bf166cb89eb55f0593404e4e933ab605e803" OR "a39b57032dbb2335499a51e13470a7cd5d86b138" OR "41cc2b15c662bc001c0eb92f6cc222934f0beeea" OR "d209430d6af54792371174e70e27dd11d3def7a7" OR "1c6452026c56efd2c94cea7e0f671eb55515edb0" OR "c6b41d3afdcdcaf9f442bbe772f5da871801fd5a" OR "4923d460e22fbbf165bbbaba168e5a46b8157d9f" OR "f201504bd96e81d0d350c3a8332593ee1c9e09de" OR "ddd2db1127632a2a52943a2fe516a2e7d05d70d2")
index: wazuh-alerts-3.x-*
name: 440a56bf-7873-4439-940a-1c8a671073c2_0
priority: 2
realert:
minutes: 0
type: any
alert:
- debug
description: Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.
filter:
- query:
query_string:
query: (data.win.system.eventID:"257" AND QNAME:("asyspy256.ddns.net" OR "hotkillmail9sddcc.ddns.net" OR "rosaf112.ddns.net" OR "cvdfhjh1231.myftp.biz" OR "sz2016rose.ddns.net" OR "dffwescwer4325.myftp.biz" OR "cvdfhjh1231.ddns.net"))
index: wazuh-alerts-3.x-*
name: 440a56bf-7873-4439-940a-1c8a671073c2-2_0
priority: 2
realert:
minutes: 0
type: any
alert:
- debug
description: Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.
filter:
- query:
query_string:
query: (sha1:("e570585edc69f9074cb5e8a790708336bd45ca0f") AND (NOT (data.win.eventdata.image.keyword:(*\:\\Program\ Files\(x86\)\\* OR *\:\\Program\ Files\\*))))
index: wazuh-alerts-3.x-*
name: 440a56bf-7873-4439-940a-1c8a671073c2-3_0
priority: 2
realert:
minutes: 0
type: any