Potential Winnti Dropper Activity

 Original Source: [Sigma source]
Title: Potential Winnti Dropper Activity
Status: test
Description:Detects files dropped by Winnti as described in RedMimicry Winnti playbook
References:
  -https://redmimicry.com/posts/redmimicry-winnti/#dropper
Author: Alexander Rausch
Date: 2020-06-24
modified:2023-01-05
Tags:
  • -'attack.stealth'
  • -'attack.t1027'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith:
      -'\gthread-3.6.dll'
      -'\sigcmm-2.4.dll'
      -'\Windows\Temp\tmp.bat'

  condition:selection
Falsepositives:
  -Unknown
Level: high