Renamed BOINC Client Execution

 Original Source: [Sigma source]
Title: Renamed BOINC Client Execution
Status: test
Description:Detects the execution of a renamed BOINC binary.
References:
  -https://boinc.berkeley.edu/
  -https://www.virustotal.com/gui/file/91e405e8a527023fb8696624e70498ae83660fe6757cef4871ce9bcc659264d3/details
  -https://www.huntress.com/blog/fake-browser-updates-lead-to-boinc-volunteer-computing-software
Author: Matt Anderson (Huntress)
Date: 2024-07-23
modified:None
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1553'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    OriginalFileName: 'BOINC.exe'
  filter_main_legit_name:
    Image|endswith: '\BOINC.exe'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium