Suspicious Unsigned Thor Scanner Execution

 Original Source: [Sigma source]
Title: Suspicious Unsigned Thor Scanner Execution
Status: stable
Description:Detects loading and execution of an unsigned thor scanner binary.
References:
  -Internal Research
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-10-29
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.001'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith:
      -'\thor.exe'
      -'\thor64.exe'

    ImageLoaded|endswith:
      -'\thor.exe'
      -'\thor64.exe'

  filter_main:
    Signed: 'true'
    SignatureStatus: 'valid'
    Signature: 'Nextron Systems GmbH'
  condition:selection and not filter_main
Falsepositives:
  -Other legitimate binaries named "thor.exe" that aren't published by Nextron Systems
Level: high