Antivirus - Exploitation Framework Signature

 Original Source: [Sigma source]
Title: Antivirus - Exploitation Framework Signature
Status: stable
Description:Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
References:
  -https://www.nextron-systems.com/?s=antivirus
  -https://www.virustotal.com/gui/file/925b0b28472d4d79b4bf92050e38cc2b8f722691c713fc28743ac38551bc3797
  -https://www.virustotal.com/gui/file/8f8daabe1c8ceb5710949283818e16c4aa8059bf2ce345e2f2c90b8692978424
  -https://www.virustotal.com/gui/file/d9669f7e3eb3a9cdf6a750eeb2ba303b5ae148a43e36546896f1d1801e912466
Author: Florian Roth (Nextron Systems), Arnim Rupp
Date: 2018-09-09
modified:2026-06-15
Tags:
  • -'attack.execution'
  • -'attack.t1203'
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • category: antivirus
Detection:
  selection:
    Signature|contains:
      -'ATK/Cobalt'
      -'Backdoor.Cobalt'
      -'Beacon'
      -'Brutel'
      -'BruteR'
      -'CbltStr'
      -'CobaltStr'
      -'COBALT.SMD'
      -'COBEACON'
      -'Cometer'
      -'Exploit.Script.CVE'
      -'IISExchgSpawnCMD'
      -'Metasploit'
      -'Meterpreter'
      -'MeteTool'
      -'Mpreter'
      -'MsfShell'
      -'PowerSploit'
      -'Razy'
      -'Rozena'
      -'Sbelt'
      -'Seatbelt'
      -'Sliver'
      -'Swrort'

  condition:selection
Falsepositives:
  -Unlikely
Level: critical