This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potentially Suspicious Cabinet File Expansion
Original Source:
[Sigma source]
Title:
Potentially Suspicious Cabinet File Expansion
Status:
test
Description:
Detects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks
References:
-https://labs.sentinelone.com/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll
-https://blog.malwarebytes.com/threat-intelligence/2021/08/new-variant-of-konni-malware-used-in-campaign-targetting-russia/
Author:
Bhabesh Raj, X__Junior (Nextron Systems)
Date:
2021-07-30
modified:
2024-11-13
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection_cmd:
Image|endswith
:
'\expand.exe'
CommandLine|contains|windash
:
'-F:'
selection_folders_1:
CommandLine|contains
:
-':\Perflogs\'
-':\ProgramData'
-':\Users\Public\'
-':\Windows\Temp\'
-'\Admin$\'
-'\AppData\Local\Temp\'
-'\AppData\Roaming\'
-'\C$\'
-'\Temporary Internet'
selection_folders_2:
- CommandLine|contains|all
:
- ':\Users\'
- '\Favorites\'
- CommandLine|contains|all
:
- ':\Users\'
- '\Favourites\'
- CommandLine|contains|all
:
- ':\Users\'
- '\Contacts\'
filter_optional_dell:
ParentImage
:
'C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe'
CommandLine|contains
:
'C:\ProgramData\Dell\UpdateService\Temp\'
condition
:
selection_cmd and 1 of selection_folders_* and not 1 of filter_optional_*
Falsepositives:
-System administrator Usage
Level:
medium