This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
PUA - Ngrok Execution
Original Source:
[Sigma source]
Title:
PUA - Ngrok Execution
Status:
test
Description:
Detects the use of Ngrok, a utility used for port forwarding and tunneling, often used by threat actors to make local protected services publicly available. Involved domains are bin.equinox.io for download and *.ngrok.io for connections.
References:
-https://ngrok.com/docs
-https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html
-https://stackoverflow.com/questions/42442320/ssh-tunnel-to-ngrok-and-initiate-rdp
-https://www.virustotal.com/gui/file/58d21840d915aaf4040ceb89522396124c82f325282f805d1085527e1e2ccfa1/detection
-https://cybleinc.com/2021/02/15/ngrok-platform-abused-by-hackers-to-deliver-a-new-wave-of-phishing-attacks/
-https://twitter.com/xorJosh/status/1598646907802451969
-https://www.softwaretestinghelp.com/how-to-use-ngrok/
Author:
Florian Roth (Nextron Systems)
Date:
2021-05-14
modified:
2023-02-21
Tags:
-'attack.command-and-control'
-'attack.t1572'
Logsource:
category: process_creation
product: windows
Detection:
selection1:
CommandLine|contains
:
-' tcp 139'
-' tcp 445'
-' tcp 3389'
-' tcp 5985'
-' tcp 5986'
selection2:
CommandLine|contains|all
:
-' start '
-'--all'
-'--config'
-'.yml'
selection3:
Image|endswith
:
'ngrok.exe'
CommandLine|contains
:
-' tcp '
-' http '
-' authtoken '
selection4:
CommandLine|contains
:
-'.exe authtoken '
-'.exe start --all'
condition
:
1 of selection*
Falsepositives:
-Another tool that uses the command line switches of Ngrok
-Ngrok http 3978 (https://learn.microsoft.com/en-us/azure/bot-service/bot-service-debug-channel-ngrok?view=azure-bot-service-4.0)
Level:
high