Title:
Renamed MegaSync Execution
Status:
test
Description:Detects the execution of a renamed MegaSync.exe as seen used by ransomware families like Nefilim, Sodinokibi, Pysa, and Conti.
References:
-https://redcanary.com/blog/rclone-mega-extortion/
Author: Sittikorn S
Date: 2021-06-22
modified:2023-02-03
Tags:
- -'attack.stealth'
- -'attack.t1218'
Logsource:
- product: windows
- category: process_creation
Detection:
selection:
OriginalFileName:
'megasync.exe'
filter:
Image|endswith:
'\megasync.exe'
condition:
selection and not filter
Falsepositives:
-Software that illegally integrates MegaSync in a renamed form
-Administrators that have renamed MegaSync
Level:
high