This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
HackTool - Inveigh Execution Artefacts
Original Source:
[Sigma source]
Title:
HackTool - Inveigh Execution Artefacts
Status:
test
Description:
Detects the presence and execution of Inveigh via dropped artefacts
References:
-https://github.com/Kevin-Robertson/Inveigh/blob/29d9e3c3a625b3033cdaf4683efaafadcecb9007/Inveigh/Support/Output.cs
-https://github.com/Kevin-Robertson/Inveigh/blob/29d9e3c3a625b3033cdaf4683efaafadcecb9007/Inveigh/Support/Control.cs
-https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-10-24
modified:
2024-06-27
Tags:
-'attack.command-and-control'
-'attack.t1219.002'
Logsource:
product: windows
category: file_event
Detection:
selection:
TargetFilename|endswith
:
-'\Inveigh-Log.txt'
-'\Inveigh-Cleartext.txt'
-'\Inveigh-NTLMv1Users.txt'
-'\Inveigh-NTLMv2Users.txt'
-'\Inveigh-NTLMv1.txt'
-'\Inveigh-NTLMv2.txt'
-'\Inveigh-FormInput.txt'
-'\Inveigh.dll'
-'\Inveigh.exe'
-'\Inveigh.ps1'
-'\Inveigh-Relay.ps1'
condition
:
selection
Falsepositives:
-Unlikely
Level:
critical