Potentially Suspicious Ping/Copy Command Combination

 Original Source: [Sigma source]
Title: Potentially Suspicious Ping/Copy Command Combination
Status: test
Description:Detects uncommon and potentially suspicious one-liner command containing both "ping" and "copy" at the same time, which is usually used by malware.
References:
  -Internal Research
Author: X__Junior (Nextron Systems)
Date: 2023-07-18
modified:2024-03-06
Tags:
  • -'attack.stealth'
  • -'attack.t1070.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_cmd:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_action:
    CommandLine|contains|all:
      -'ping'
      -'copy '

  selection_cli_1:
    CommandLine|contains|windash: ' -n '
  selection_cli_2:
    CommandLine|contains|windash: ' -y '
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium