Renamed Gpg.EXE Execution

 Original Source: [Sigma source]
Title: Renamed Gpg.EXE Execution
Status: test
Description:Detects the execution of a renamed "gpg.exe". Often used by ransomware and loaders to decrypt/encrypt data.
References:
  -https://securelist.com/locked-out/68960/
Author: Nasreddine Bencherchali (Nextron Systems), frack113
Date: 2023-08-09
modified:None
Tags:
  • -'attack.impact'
  • -'attack.t1486'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    OriginalFileName: 'gpg.exe'
  filter_main_img:
    Image|endswith:
      -'\gpg.exe'
      -'\gpg2.exe'

  condition:selection and not 1 of filter_main_*
Falsepositives:
Level: high