Shadow Copies Deletion Using Operating Systems Utilities

 Original Source: [Sigma source]
Title: Shadow Copies Deletion Using Operating Systems Utilities
Status: stable
Description:Shadow Copies deletion using operating systems utilities
References:
  -https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment
  -https://blog.talosintelligence.com/2017/05/wannacry.html
  -https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/new-teslacrypt-ransomware-arrives-via-spam/
  -https://www.bleepingcomputer.com/news/security/why-everyone-should-disable-vssadmin-exe-now/
  -https://www.hybrid-analysis.com/sample/ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa?environmentId=100
  -https://github.com/Neo23x0/Raccine#the-process
  -https://github.com/Neo23x0/Raccine/blob/20a569fa21625086433dcce8bb2765d0ea08dcb6/yara/gen_ransomware_command_lines.yar
  -https://redcanary.com/blog/intelligence-insights-october-2021/
  -https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackbyte-exbyte-ransomware
Author: Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)
Date: 2019-10-22
modified:2022-11-03
Tags:
  • -'attack.impact'
  • -'attack.stealth'
  • -'attack.t1070'
  • -'attack.t1490'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection1_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wmic.exe'
      - '\vssadmin.exe'
      - '\diskshadow.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
      - 'wmic.exe'
      - 'VSSADMIN.EXE'
      - 'diskshadow.exe'
  selection1_cli:
    CommandLine|contains|all:
      -'shadow'
      -'delete'

  selection2_img:
Image|endswith:'\wbadmin.exe' OriginalFileName:'WBADMIN.EXE'   selection2_cli:
    CommandLine|contains|all:
      -'delete'
      -'catalog'
      -'quiet'

  selection3_img:
Image|endswith:'\vssadmin.exe' OriginalFileName:'VSSADMIN.EXE'   selection3_cli:
    CommandLine|contains|all:
      -'resize'
      -'shadowstorage'

    CommandLine|contains:
      -'unbounded'
      -'/MaxSize='

  condition:(all of selection1*) or (all of selection2*) or (all of selection3*)
Falsepositives:
  -Legitimate Administrator deletes Shadow Copies using operating systems utilities for legitimate reason
  -LANDesk LDClient Ivanti-PSModule (PS EncodedCommand)
Level: high