mirror of
https://github.com/ditekshen/detection
synced 2026-06-08 13:49:35 +00:00
Add and update rules. Fix #17
This commit is contained in:
@@ -8,3 +8,5 @@ ditekSHen.INDICATOR.Win.RMM.PDQConnectAgent;Engine:51-255,Target:1;((0|1|2|3|4|5
|
||||
ditekSHen.INDICATOR.Win.RMM.PulseWay;Engine:51-255,Target:1;(0|1|2|3|4|5|6|7|8)>7;4d4d2e4d6f6e69746f722e;52444167656e7453657373696f6e53657474696e677356;436865636b466f724d61634f5352656d6f74654465736b746f70557064617465436f6d706c657465644576656e74;436f6e6669726d4167656e7453746172746564;47657453637265656e73686f74;556e6c6f616452656d6f74654465736b746f70446c6c73;4374726c416c7444656c65746550726f63;2437636663336238382d366463342d343966632d396630612d626639653931313361313464;636f6d70757465726d6f6e69746f722e6d6d736f66742e726f
|
||||
ditekSHen.INDICATOR.Win.RMM.PulseWay;Engine:51-255,Target:1;(0|1|2|3|4|5|6|7|8)>7;4d4d2e4d6f6e69746f722e;52444167656e7453657373696f6e53657474696e677356;436865636b466f724d61634f5352656d6f74654465736b746f70557064617465436f6d706c657465644576656e74;436f6e6669726d4167656e7453746172746564;47657453637265656e73686f74;556e6c6f616452656d6f74654465736b746f70446c6c73;4374726c416c7444656c65746550726f63;2437636663336238382d366463342d343966632d396630612d626639653931313361313464;636f6d70757465726d6f6e69746f722e6d6d736f66742e726f
|
||||
ditekSHen.INDICATOR.Win.RMM.ManageEngine-ZohoMeeting;Engine:51-255,Target:1;0&1&2&3&4&5&6&7;55454d53202d2052656d6f746520436f6e74726f6c::w;4167656e74486f6f6b2e646c6c::w;62696e5c436c69656e744175746848616e646c65722e646c6c::w;496e7374616c6c20686f6f6b2e2e2e2e::w;696e6469612e616476656e746e65742e636f6d2f6d6565742e7361733f6b3d;6463546370536f636b65743a3a;25732f25733f636c69656e7449643d25732673657373696f6e49643d257326636c69656e744e616d653d2573267469636b65743d257326636f6e6e656374696f6e49643d2573;2e5c656e67696e65735c6363676f73745c676f73745f
|
||||
ditekSHen.INDICATOR.Win.RMM.Atera;Engine:51-255,Target:1;(0&1&2&3&4)>2;534f4654574152455c4154455241204e6574776f726b735c416c7068614167656e74::w;416c706861436f6e74726f6c4167656e745c6f626a5c52656c656173655c41746572614167656e742e706462;416c706861436f6e74726f6c4167656e742e436c6f75644c6f67734d616e616765722b3c3e;4d6f6e69746f72696e672026204d616e6167656d656e74204167656e74206279204154455241::aw;6167656e742d6170692d7b307d2e61746572612e636f6d::w
|
||||
ditekSHen.INDICATOR.Win.RMM.SplashtopStreamer;Engine:51-255,Target:1;(0&1&2&3&4&5)>3;5c736c6176655c776f726b73706163655c4749545f57494e5:iiqf5352535f466f726d616c5c536f757263655c697269737365727665725c;536f6674776172655c53706c617368746f7020496e632e5c53706c617368746f70::w;2e6170692e73706c617368746f702e636f6d::w;726573746172746564207468652073747265616d65722e256e4170702076657273696f6e3a202531::w;53706c617368746f702d53706c617368746f702053747265616d65722d::w;5b52656d6f766553747265616d65725d2053656e64206d7367203220636c6f75642825643a25643a256429::w
|
||||
|
||||
@@ -341,3 +341,79 @@ rule INDICATOR_RMM_ManageEngine_CERT {
|
||||
)
|
||||
}
|
||||
*/
|
||||
|
||||
rule INDICATOR_RMM_Atera {
|
||||
meta:
|
||||
author = "ditekSHen"
|
||||
description = "Detects Atera. Review RMM Inventory"
|
||||
clamav1 = "INDICATOR.Win.RMM.Atera"
|
||||
reference1 = "https://github.com/ditekshen/detection/blob/master/RMM_Inventory.csv"
|
||||
reference2 = "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a"
|
||||
reference3 = "https://www.cisa.gov/sites/default/files/2023-06/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf"
|
||||
reference4 = "https://www.cisa.gov/sites/default/files/2023-08/JCDC_RMM_Cyber_Defense_Plan_TLP_CLEAR_508c_1.pdf"
|
||||
strings:
|
||||
$s1 = "SOFTWARE\\ATERA Networks\\AlphaAgent" wide
|
||||
$s2 = "Monitoring & Management Agent by ATERA" ascii wide
|
||||
$s3 = "agent-api-{0}.atera.com" wide
|
||||
$s4 = "agent-api.atera.com" wide
|
||||
$s5 = "acontrol.atera.com" wide
|
||||
$s6 = /Agent\/(PingReply|GetCommandsFallback|GetCommands|GetTime|GetEnvironmentStatus|GetRecurringPackages|AgentStarting|AcknowledgeCommands)/ wide
|
||||
$s7 = "\\AlphaControlAgent\\obj\\Release\\AteraAgent.pdb" ascii
|
||||
$s8 = "AteraWebAddress" ascii
|
||||
$s9 = "AlphaControlAgent.CloudLogsManager+<>" ascii
|
||||
condition:
|
||||
uint16(0) == 0x5a4d and 4 of them
|
||||
}
|
||||
|
||||
rule INDICATOR_RMM_Atera_CERT {
|
||||
meta:
|
||||
author = "ditekSHen"
|
||||
description = "Detects Atera by certificate. Review RMM Inventory"
|
||||
clamav1 = "INDICATOR.Win.RMM.Atera"
|
||||
reference1 = "https://github.com/ditekshen/detection/blob/master/RMM_Inventory.csv"
|
||||
reference2 = "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a"
|
||||
reference3 = "https://www.cisa.gov/sites/default/files/2023-06/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf"
|
||||
reference4 = "https://www.cisa.gov/sites/default/files/2023-08/JCDC_RMM_Cyber_Defense_Plan_TLP_CLEAR_508c_1.pdf"
|
||||
condition:
|
||||
uint16(0) == 0x5a4d and
|
||||
for any i in (0..pe.number_of_signatures): (
|
||||
pe.signatures[i].issuer contains "DigiCert" and
|
||||
pe.signatures[i].subject contains "Atera Networks Ltd"
|
||||
)
|
||||
}
|
||||
|
||||
rule INDICATOR_RMM_SplashtopStreamer {
|
||||
meta:
|
||||
author = "ditekSHen"
|
||||
description = "Detects Splashtop Streamer. Review RMM Inventory"
|
||||
clamav1 = "INDICATOR.Win.RMM.SplashtopStreamer"
|
||||
reference1 = "https://github.com/ditekshen/detection/blob/master/RMM_Inventory.csv"
|
||||
reference2 = "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a"
|
||||
reference3 = "https://www.cisa.gov/sites/default/files/2023-06/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf"
|
||||
reference4 = "https://www.cisa.gov/sites/default/files/2023-08/JCDC_RMM_Cyber_Defense_Plan_TLP_CLEAR_508c_1.pdf"
|
||||
strings:
|
||||
$s1 = "\\slave\\workspace\\GIT_WIN_SRS_Formal\\Source\\irisserver\\" ascii
|
||||
$s2 = ".api.splashtop.com" wide
|
||||
$s3 = "Software\\Splashtop Inc.\\Splashtop" wide
|
||||
$s4 = "restarted the streamer.%nApp version: %1" wide
|
||||
$s5 = "Splashtop-Splashtop Streamer-" wide
|
||||
$s6 = "[RemoveStreamer] Send msg 2 cloud(%d:%d:%d)" wide
|
||||
condition:
|
||||
uint16(0) == 0x5a4d and 4 of them
|
||||
}
|
||||
|
||||
rule INDICATOR_RMM_SplashtopStreamer_CERT {
|
||||
meta:
|
||||
author = "ditekSHen"
|
||||
description = "Detects Splashtop Streamer by certificate. Review RMM Inventory"
|
||||
reference1 = "https://github.com/ditekshen/detection/blob/master/RMM_Inventory.csv"
|
||||
reference2 = "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a"
|
||||
reference3 = "https://www.cisa.gov/sites/default/files/2023-06/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf"
|
||||
reference4 = "https://www.cisa.gov/sites/default/files/2023-08/JCDC_RMM_Cyber_Defense_Plan_TLP_CLEAR_508c_1.pdf"
|
||||
condition:
|
||||
uint16(0) == 0x5a4d and
|
||||
for any i in (0..pe.number_of_signatures): (
|
||||
pe.signatures[i].issuer contains "DigiCert" and
|
||||
pe.signatures[i].subject contains "Splashtop Inc."
|
||||
)
|
||||
}
|
||||
|
||||
@@ -2380,7 +2380,7 @@ rule INDICATOR_SUSPICIOUS_IMG_Embedded_B64_EXE {
|
||||
$h1 = "TVqQA" ascii
|
||||
$h2 = "AQqVT" ascii
|
||||
condition:
|
||||
(uint32(0) == 0xe0ffd8ff or uint32(0) == 0x474e5089 or uint16(0) == 0x4d42) and ((2 of ($m*)) or (1 of ($h*)))
|
||||
(uint32(0) == 0xd8ff or uint32(0) == 0x474e5089 or uint16(0) == 0x4d42) and ((2 of ($m*)) or (1 of ($h*)))
|
||||
}
|
||||
|
||||
rule INDICATOR_SUSPICIOUS_EXE_TransferSh_URL {
|
||||
|
||||
+9
-1
@@ -3854,7 +3854,7 @@ rule MALWARE_Linux_RansomExx {
|
||||
$s7 = "list_dir" fullword ascii
|
||||
$s8 = "ctr_drbg_update_internal" fullword ascii
|
||||
condition:
|
||||
uint16(0) == 0x457f and (5 of ($s*) or 6 of ($s*) or (3 of ($c*) and 3 of ($s*)))
|
||||
uint16(0) == 0x457f and (5 of ($c*) or 6 of ($s*) or (3 of ($c*) and 3 of ($s*)))
|
||||
}
|
||||
|
||||
rule MALWARE_Win_TrickbotModule {
|
||||
@@ -9863,6 +9863,8 @@ rule MALWARE_Win_LummaStealer {
|
||||
$s9 = "- Screen Resoluton:" ascii
|
||||
$s10 = "lid=%s" ascii
|
||||
$s11 = "&ver=" ascii
|
||||
$s12 = "769cb9aa22f4ccc412f9cbc81feedd" fullword wide
|
||||
$s13 = "gapi-node.io" fullword ascii
|
||||
condition:
|
||||
uint16(0) == 0x5a4d and (all of ($x*) or (1 of ($x*) and 2 of ($s*)) or 5 of ($s*) or 7 of them)
|
||||
}
|
||||
@@ -10628,6 +10630,12 @@ rule MALWARE_Win_RustyStealer {
|
||||
$s8 = /\\logscx\\(passwords_|cookies_|creditcards_)/ ascii
|
||||
$s9 = "VirtualBoxVBoxVMWareVMCountry" ascii
|
||||
$s10 = "New Log From ( / )" ascii
|
||||
$s11 = "BrowserChromeKometaOrbitumSputnikTorchUranuCozMediaVivaldiAtomMail" ascii
|
||||
$s12 = "BrowserBraveSoftwareCentBrowserChedotChrome" ascii
|
||||
$s13 = "ChromeKometaOrbitumSputnikTorchUranuCozMediaVivaldi" ascii
|
||||
$s14 = "hostnameencryptedUsernameencryptedPasswordstruct" ascii
|
||||
$s15 = "encryptedPassword" fullword ascii
|
||||
$s16 = "AutoFill@~" fullword ascii
|
||||
condition:
|
||||
uint16(0) == 0x5a4d and 6 of them
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user