HackTool - Inveigh Execution Artefacts

 Original Source: [Sigma source]
Title: HackTool - Inveigh Execution Artefacts
Status: test
Description:Detects the presence and execution of Inveigh via dropped artefacts
References:
  -https://github.com/Kevin-Robertson/Inveigh/blob/29d9e3c3a625b3033cdaf4683efaafadcecb9007/Inveigh/Support/Output.cs
  -https://github.com/Kevin-Robertson/Inveigh/blob/29d9e3c3a625b3033cdaf4683efaafadcecb9007/Inveigh/Support/Control.cs
  -https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-24
modified:2024-06-27
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith:
      -'\Inveigh-Log.txt'
      -'\Inveigh-Cleartext.txt'
      -'\Inveigh-NTLMv1Users.txt'
      -'\Inveigh-NTLMv2Users.txt'
      -'\Inveigh-NTLMv1.txt'
      -'\Inveigh-NTLMv2.txt'
      -'\Inveigh-FormInput.txt'
      -'\Inveigh.dll'
      -'\Inveigh.exe'
      -'\Inveigh.ps1'
      -'\Inveigh-Relay.ps1'

  condition:selection
Falsepositives:
  -Unlikely
Level: critical