PUA - Ngrok Execution

 Original Source: [Sigma source]
Title: PUA - Ngrok Execution
Status: test
Description:Detects the use of Ngrok, a utility used for port forwarding and tunneling, often used by threat actors to make local protected services publicly available. Involved domains are bin.equinox.io for download and *.ngrok.io for connections.
References:
  -https://ngrok.com/docs
  -https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html
  -https://stackoverflow.com/questions/42442320/ssh-tunnel-to-ngrok-and-initiate-rdp
  -https://www.virustotal.com/gui/file/58d21840d915aaf4040ceb89522396124c82f325282f805d1085527e1e2ccfa1/detection
  -https://cybleinc.com/2021/02/15/ngrok-platform-abused-by-hackers-to-deliver-a-new-wave-of-phishing-attacks/
  -https://twitter.com/xorJosh/status/1598646907802451969
  -https://www.softwaretestinghelp.com/how-to-use-ngrok/
Author: Florian Roth (Nextron Systems)
Date: 2021-05-14
modified:2023-02-21
Tags:
  • -'attack.command-and-control'
  • -'attack.t1572'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection1:
    CommandLine|contains:
      -' tcp 139'
      -' tcp 445'
      -' tcp 3389'
      -' tcp 5985'
      -' tcp 5986'

  selection2:
    CommandLine|contains|all:
      -' start '
      -'--all'
      -'--config'
      -'.yml'

  selection3:
    Image|endswith: 'ngrok.exe'
    CommandLine|contains:
      -' tcp '
      -' http '
      -' authtoken '

  selection4:
    CommandLine|contains:
      -'.exe authtoken '
      -'.exe start --all'

  condition:1 of selection*
Falsepositives:
  -Another tool that uses the command line switches of Ngrok
  -Ngrok http 3978 (https://learn.microsoft.com/en-us/azure/bot-service/bot-service-debug-channel-ngrok?view=azure-bot-service-4.0)
Level: high