Portable Gpg.EXE Execution

 Original Source: [Sigma source]
Title: Portable Gpg.EXE Execution
Status: test
Description:Detects the execution of "gpg.exe" from uncommon location. Often used by ransomware and loaders to decrypt/encrypt data.
References:
  -https://www.trendmicro.com/vinfo/vn/threat-encyclopedia/malware/ransom.bat.zarlock.a
  -https://securelist.com/locked-out/68960/
  -https://github.com/redcanaryco/atomic-red-team/blob/c4097dc7ed14d7f7d08c89d148c4307097e8c294/atomics/T1486/T1486.md
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
Date: 2023-08-06
modified:2023-11-10
Tags:
  • -'attack.impact'
  • -'attack.t1486'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    - Image|endswith:
      - '\gpg.exe'
      - '\gpg2.exe'
OriginalFileName:'gpg.exe' Description:'GnuPG’s OpenPGP tool'   filter_main_legit_location:
    Image|contains:
      -':\Program Files (x86)\GNU\GnuPG\bin\'
      -':\Program Files (x86)\GnuPG VS-Desktop\'
      -':\Program Files (x86)\GnuPG\bin\'
      -':\Program Files (x86)\Gpg4win\bin\'

  condition:selection and not 1 of filter_main_*
Falsepositives:
Level: medium