Renamed MegaSync Execution

 Original Source: [Sigma source]
Title: Renamed MegaSync Execution
Status: test
Description:Detects the execution of a renamed MegaSync.exe as seen used by ransomware families like Nefilim, Sodinokibi, Pysa, and Conti.
References:
  -https://redcanary.com/blog/rclone-mega-extortion/
Author: Sittikorn S
Date: 2021-06-22
modified:2023-02-03
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    OriginalFileName: 'megasync.exe'
  filter:
    Image|endswith: '\megasync.exe'
  condition:selection and not filter
Falsepositives:
  -Software that illegally integrates MegaSync in a renamed form
  -Administrators that have renamed MegaSync
Level: high