diff --git a/detections/endpoint/allow_operation_with_consent_admin.yml b/detections/endpoint/allow_operation_with_consent_admin.yml index 219f2cc83b..36c69cc884 100644 --- a/detections/endpoint/allow_operation_with_consent_admin.yml +++ b/detections/endpoint/allow_operation_with_consent_admin.yml @@ -40,6 +40,7 @@ tags: analytic_story: - Ransomware - Windows Registry Abuse + - Azorult confidence: 50 context: - Source:Endpoint diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 6bdebc0f31..da046b0d60 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -31,6 +31,7 @@ tags: - Disabling Security Tools - Trickbot - WhisperGate + - Azorult asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/endpoint/chcp_command_execution.yml b/detections/endpoint/chcp_command_execution.yml index d9651cdf68..f3da51b3d1 100644 --- a/detections/endpoint/chcp_command_execution.yml +++ b/detections/endpoint/chcp_command_execution.yml @@ -27,6 +27,7 @@ references: tags: analytic_story: - IcedID + - Azorult confidence: 30 context: - Source:Endpoint diff --git a/detections/endpoint/cmd_carry_out_string_command_parameter.yml b/detections/endpoint/cmd_carry_out_string_command_parameter.yml index 7144a751a6..37830f5cf9 100644 --- a/detections/endpoint/cmd_carry_out_string_command_parameter.yml +++ b/detections/endpoint/cmd_carry_out_string_command_parameter.yml @@ -36,6 +36,7 @@ tags: - WhisperGate - Hermetic Wiper - Living Off The Land + - Azorult automated_detection_testing: passed confidence: 50 context: diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index 4ab022ef07..42a9b1a862 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -26,6 +26,7 @@ references: [] tags: analytic_story: - DHS Report TA18-074A + - Azorult asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 2420c28776..6123aacee2 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -26,6 +26,7 @@ tags: analytic_story: - 'Emotet Malware DHS Report TA18-201A ' - Suspicious Command-Line Executions + - Azorult asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml index b5b16d85d0..67493e64e5 100644 --- a/detections/endpoint/disable_defender_blockatfirstseen_feature.yml +++ b/detections/endpoint/disable_defender_blockatfirstseen_feature.yml @@ -34,6 +34,7 @@ tags: analytic_story: - IceID - Windows Registry Abuse + - Azorult confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/disable_defender_enhanced_notification.yml b/detections/endpoint/disable_defender_enhanced_notification.yml index b55567d231..51543a90d4 100644 --- a/detections/endpoint/disable_defender_enhanced_notification.yml +++ b/detections/endpoint/disable_defender_enhanced_notification.yml @@ -34,6 +34,7 @@ tags: analytic_story: - IceID - Windows Registry Abuse + - Azorult confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/disable_defender_spynet_reporting.yml b/detections/endpoint/disable_defender_spynet_reporting.yml index dcd559b377..d50493ac2d 100644 --- a/detections/endpoint/disable_defender_spynet_reporting.yml +++ b/detections/endpoint/disable_defender_spynet_reporting.yml @@ -33,6 +33,7 @@ tags: analytic_story: - IceID - Windows Registry Abuse + - Azorult confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml index f4d6e75115..dc17013676 100644 --- a/detections/endpoint/disable_defender_submit_samples_consent_feature.yml +++ b/detections/endpoint/disable_defender_submit_samples_consent_feature.yml @@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint -description: his analytic is to detect a suspicious modification of registry to disable +description: This analytic is to detect a suspicious modification of registry to disable windows defender feature. This technique is to bypassed or evade detection from Windows Defender AV product specially the submit samples feature for further analysis.. search: '| tstats `security_content_summariesonly` count from datamodel=Endpoint.Registry @@ -33,6 +33,7 @@ tags: analytic_story: - IceID - Windows Registry Abuse + - Azorult confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/disable_show_hidden_files.yml b/detections/endpoint/disable_show_hidden_files.yml index a11229d9b5..a1c0aabf8a 100644 --- a/detections/endpoint/disable_show_hidden_files.yml +++ b/detections/endpoint/disable_show_hidden_files.yml @@ -36,6 +36,7 @@ tags: analytic_story: - Windows Defense Evasion Tactics - Windows Registry Abuse + - Azorult confidence: 100 context: - Source:Endpoint diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index 27e511a6ca..7a3bca8c50 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -42,6 +42,7 @@ tags: - Ransomware - Revil Ransomware - Windows Registry Abuse + - Azorult confidence: 100 context: - Source:Endpoint diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index e229e77942..3736b1281d 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -28,6 +28,7 @@ tags: - Suspicious Windows Registry Activities - Remcos - Windows Registry Abuse + - Azorult asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/excessive_attempt_to_disable_services.yml b/detections/endpoint/excessive_attempt_to_disable_services.yml index 705e2756d5..f0be24f660 100644 --- a/detections/endpoint/excessive_attempt_to_disable_services.yml +++ b/detections/endpoint/excessive_attempt_to_disable_services.yml @@ -15,7 +15,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "sc.exe" AND Processes.process="*config*" OR Processes.process="*Disabled*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user _time span=1m | where - count >=5 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + count >=4 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `excessive_attempt_to_disable_services_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your @@ -27,6 +27,7 @@ references: tags: analytic_story: - XMRig + - Azorult confidence: 100 context: - Source:Endpoint diff --git a/detections/endpoint/excessive_usage_of_cacls_app.yml b/detections/endpoint/excessive_usage_of_cacls_app.yml index 212a964ee2..8e9522442c 100644 --- a/detections/endpoint/excessive_usage_of_cacls_app.yml +++ b/detections/endpoint/excessive_usage_of_cacls_app.yml @@ -27,6 +27,7 @@ references: tags: analytic_story: - XMRig + - Azorult confidence: 100 context: - Source:Endpoint diff --git a/detections/endpoint/excessive_usage_of_net_app.yml b/detections/endpoint/excessive_usage_of_net_app.yml index 6fa2f8f347..cb8852cdb9 100644 --- a/detections/endpoint/excessive_usage_of_net_app.yml +++ b/detections/endpoint/excessive_usage_of_net_app.yml @@ -28,6 +28,7 @@ tags: analytic_story: - XMRig - Ransomware + - Azorult confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/excessive_usage_of_sc_service_utility.yml b/detections/endpoint/excessive_usage_of_sc_service_utility.yml index 92ae980ff3..63dfe423c4 100644 --- a/detections/endpoint/excessive_usage_of_sc_service_utility.yml +++ b/detections/endpoint/excessive_usage_of_sc_service_utility.yml @@ -27,6 +27,7 @@ references: tags: analytic_story: - Ransomware + - Azorult context: - Source:Endpoint - Scope:Local diff --git a/detections/endpoint/excessive_usage_of_taskkill.yml b/detections/endpoint/excessive_usage_of_taskkill.yml index b25aed23dc..22c82d5e96 100644 --- a/detections/endpoint/excessive_usage_of_taskkill.yml +++ b/detections/endpoint/excessive_usage_of_taskkill.yml @@ -25,6 +25,7 @@ references: tags: analytic_story: - XMRig + - Azorult confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index c895a2846b..2d7567db60 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -42,6 +42,7 @@ tags: - WhisperGate - Hermetic Wiper - Industroyer2 + - Azorult automated_detection_testing: passed confidence: 70 context: diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index 0d664b3f46..c20a9a07e1 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -13,7 +13,7 @@ description: This analytic detects a potential suspicious modification of firewa testing or allowing legitimate tool or application. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*firewall*" - Processes.process = "*allowedprogram*" Processes.process = "*add*" Processes.process + Processes.process = "*allow*" Processes.process = "*add*" Processes.process = "*ENABLE*" by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` @@ -31,6 +31,7 @@ references: tags: analytic_story: - Windows Defense Evasion Tactics + - Azorult confidence: 50 context: - Source:Endpoint diff --git a/detections/endpoint/hide_user_account_from_sign_in_screen.yml b/detections/endpoint/hide_user_account_from_sign_in_screen.yml index 7948f3ac6b..7f24e93935 100644 --- a/detections/endpoint/hide_user_account_from_sign_in_screen.yml +++ b/detections/endpoint/hide_user_account_from_sign_in_screen.yml @@ -39,6 +39,7 @@ tags: analytic_story: - XMRig - Windows Registry Abuse + - Azorult confidence: 80 context: - Source:Endpoint diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index 7321aa4b1d..0afa98a8a9 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -27,6 +27,7 @@ tags: analytic_story: - Windows Defense Evasion Tactics - Windows Persistence Techniques + - Azorult asset_type: '' cis20: - CIS 8 diff --git a/detections/endpoint/icacls_deny_command.yml b/detections/endpoint/icacls_deny_command.yml index 8ff692f6cb..8cca9b176b 100644 --- a/detections/endpoint/icacls_deny_command.yml +++ b/detections/endpoint/icacls_deny_command.yml @@ -28,6 +28,7 @@ references: tags: analytic_story: - XMRig + - Azorult confidence: 80 context: - Source:Endpoint diff --git a/detections/endpoint/net_localgroup_discovery.yml b/detections/endpoint/net_localgroup_discovery.yml index 2c0e134c87..eb48b3e57d 100644 --- a/detections/endpoint/net_localgroup_discovery.yml +++ b/detections/endpoint/net_localgroup_discovery.yml @@ -29,6 +29,7 @@ tags: analytic_story: - Active Directory Discovery - Windows Discovery Techniques + - Azorult confidence: 50 context: - Source:Endpoint diff --git a/detections/endpoint/network_connection_discovery_net.yml b/detections/endpoint/network_connection_discovery_net.yml index 45a34f54d6..29133265c6 100644 --- a/detections/endpoint/network_connection_discovery_net.yml +++ b/detections/endpoint/network_connection_discovery_net.yml @@ -25,6 +25,7 @@ references: tags: analytic_story: - Active Directory Discovery + - Azorult confidence: 50 context: - Source:Endpoint diff --git a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml index 87d87b8111..57f268f033 100644 --- a/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml +++ b/detections/endpoint/non_firefox_process_access_firefox_profile_dir.yml @@ -29,6 +29,7 @@ tags: analytic_story: - FIN7 - Remcos + - Azorult confidence: 70 context: - Source:Endpoint diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index 49999e959f..46770ffccf 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -32,6 +32,7 @@ tags: - Netsh Abuse - Disabling Security Tools - DHS Report TA18-074A + - Azorult asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index c5a14cb897..c1abc8b1f7 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -56,6 +56,7 @@ tags: - IcedID - Remcos - Windows Registry Abuse + - Azorult asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 4889e6fdc1..fe86c4b9f8 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -29,6 +29,7 @@ tags: - Windows Persistence Techniques - Disabling Security Tools - NOBELIUM Group + - Azorult asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 70e44fae46..cc5a66a67f 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -31,6 +31,7 @@ tags: - NOBELIUM Group - Windows Persistence Techniques - Living Off The Land + - Azorult asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml index 000d4eb9c0..2b5dad1423 100644 --- a/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml +++ b/detections/endpoint/suspicious_scheduled_task_from_public_directory.yml @@ -32,6 +32,7 @@ tags: - Ryuk Ransomware - Windows Persistence Techniques - Living Off The Land + - Azorult confidence: 50 context: - Source:Endpoint diff --git a/detections/endpoint/windows_defender_exclusion_registry_entry.yml b/detections/endpoint/windows_defender_exclusion_registry_entry.yml index 5c350e3f69..aff252f197 100644 --- a/detections/endpoint/windows_defender_exclusion_registry_entry.yml +++ b/detections/endpoint/windows_defender_exclusion_registry_entry.yml @@ -38,6 +38,7 @@ tags: analytic_story: - Remcos - Windows Defense Evasion Tactics + - Azorult confidence: 80 context: - Source:Endpoint diff --git a/detections/endpoint/windows_disableantispyware_reg.yml b/detections/endpoint/windows_disableantispyware_reg.yml index af508a8574..5fd40bf090 100644 --- a/detections/endpoint/windows_disableantispyware_reg.yml +++ b/detections/endpoint/windows_disableantispyware_reg.yml @@ -31,6 +31,7 @@ tags: - Ryuk Ransomware - Windows Defense Evasion Tactics - Windows Registry Abuse + - Azorult asset_type: Endpoint cis20: - CIS 8 diff --git a/stories/azorult.yml b/stories/azorult.yml new file mode 100644 index 0000000000..3da6ad44f6 --- /dev/null +++ b/stories/azorult.yml @@ -0,0 +1,26 @@ +name: Azorult +id: efed5343-4ac2-42b1-a16d-da2428d0ce94 +version: 1 +date: '2022-06-09' +author: Teoderick Contreras, Splunk +description: Leverage searches that allow you to detect and investigate unusual activities + that might relate to the Azorult malware including firewall modification, icacl execution, spawning more process, botnet c2 communication, defense evasion and etc. + The AZORULT malware was first discovered in 2016 to be an information stealer that steals browsing history, cookies, ID/passwords, cryptocurrency information and more. + It can also be a downloader of other malware. A variant of this malware was able to create a new, hidden administrator account on the machine to set a registry key + to establish a Remote Desktop Protocol (RDP) connection. + Exploit kits such as Fallout Exploit Kit (EK) and phishing mails with social engineering technique are one of the major infection vectors of the AZORult malware. + The current malspam and phishing emails use fake product order requests, invoice documents and payment information requests. This Trojan-Spyware connects to command and control (C&C) servers of attacker to send and receive information. +narrative: Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption + is the goal. +references: +- https://success.trendmicro.com/dcx/s/solution/000146108-azorult-malware-information?language=en_US&sfdcIFrameOrigin=null +- https://app.any.run/tasks/a6f2ffe2-e6e2-4396-ae2e-04ea0143f2d8/ +tags: + analytic_story: Azorult + category: + - Malware + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection