PUA - SoftPerfect Netscan Execution

 Original Source: [Sigma source]
Title: PUA - SoftPerfect Netscan Execution
Status: test
Description:Detects usage of SoftPerfect's "netscan.exe". An application for scanning networks. It is actively used in-the-wild by threat actors to inspect and understand the network architecture of a victim.
References:
  -https://www.protect.airbus.com/blog/uncovering-cyber-intruders-netscan/
  -https://secjoes-reports.s3.eu-central-1.amazonaws.com/Sockbot%2Bin%2BGoLand.pdf
  -https://www.sentinelone.com/labs/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor/
  -https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/yanluowang-ransomware-attacks-continue
  -https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back/
  -https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-hive-ransomware/
  -https://www.softperfect.com/products/networkscanner/
Author: @d4ns4n_ (Wuerth-Phoenix)
Date: 2024-04-25
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1046'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\netscan.exe' Product:'Network Scanner' Description:'Application for scanning networks'   condition:selection
Falsepositives:
  -Legitimate administrator activity
Level: medium