Suspicious Appended Extension

 Original Source: [Sigma source]
Title: Suspicious Appended Extension
Status: test
Description:Detects file renames where the target filename uses an uncommon double extension. Could indicate potential ransomware activity renaming files and adding a custom extension to the encrypted files, such as ".jpg.crypted", ".docx.locky", etc.
References:
  -https://app.any.run/tasks/d66ead5a-faf4-4437-93aa-65785afaf9e5/
  -https://blog.cyble.com/2022/08/10/onyx-ransomware-renames-its-leak-site-to-vsop/
Author: frack113
Date: 2022-07-16
modified:2023-11-11
Tags:
  • -'attack.impact'
  • -'attack.t1486'
Logsource:
  • product: windows
  • category: file_rename
  • definition: Requirements: Microsoft-Windows-Kernel-File Provider with at least the KERNEL_FILE_KEYWORD_RENAME_SETLINK_PATH keyword
Detection:
  selection:
    SourceFilename|endswith:
      -'.doc'
      -'.docx'
      -'.jpeg'
      -'.jpg'
      -'.lnk'
      -'.pdf'
      -'.png'
      -'.pst'
      -'.rtf'
      -'.xls'
      -'.xlsx'

    TargetFilename|contains:
      -'.doc.'
      -'.docx.'
      -'.jpeg.'
      -'.jpg.'
      -'.lnk.'
      -'.pdf.'
      -'.png.'
      -'.pst.'
      -'.rtf.'
      -'.xls.'
      -'.xlsx.'

  filter_main_generic:
    TargetFilename|endswith:
      -'.backup'
      -'.bak'
      -'.old'
      -'.orig'
      -'.temp'
      -'.tmp'

  filter_optional_anaconda:
    TargetFilename|contains: ':\ProgramData\Anaconda3\'
    TargetFilename|endswith: '.c~'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Backup software
Level: medium