Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2022-09-29 11:11:53 -07:00
committed by GitHub
10 changed files with 260 additions and 9 deletions
@@ -37,6 +37,7 @@ tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- AgentTesla
confidence: 80
context:
- Source:Endpoint
@@ -1,7 +1,7 @@
name: Registry Keys Used For Persistence
id: f5f6af30-7aa7-4295-bfe9-07fe87c01a4b
version: 8
date: '2022-07-20'
version: 9
date: '2022-09-19'
author: Jose Hernandez, David Dorsey, Teoderick Contreras, Rod Soto, Splunk
type: TTP
datamodel:
@@ -10,6 +10,7 @@ description: The search looks for modifications to registry keys that can be use
to launch an application or service at system startup.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnce
OR Registry.registry_path=*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartupApproved\\Run
OR Registry.registry_path=*\\currentversion\\run* OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls*
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify*
OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet*
@@ -0,0 +1,72 @@
name: Windows File Transfer Protocol In Non-Common Process Path
id: 0f43758f-1fe9-470a-a9e4-780acc4d5407
version: 1
date: '2022-09-16'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies a possible windows application having a FTP connection
in a non common installation path in windows operating system.This network protocol is being used by adversaries,
threat actors and malware like AgentTesla as a command and control communication to transfer its collected stolen information
like the desktop screenshots, browser information and system information of a targeted or compromised host.
search: '`sysmon` EventCode=3 NOT(Image IN("*\\program files*", "*\\windows\\system32\\*","*\\windows\\SysWOW64\\*"))
(DestinationPortName="ftp" OR DestinationPort=21)
| stats count min(_time) as firstTime max(_time) as lastTime by Image DestinationPort DestinationPortName DestinationHostname DestinationIp
SourcePort SourcePortName Protocol SourceHostname Computer user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_file_transfer_protocol_in_non_common_process_path_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name and sysmon eventcode = 3 connection events from your endpoints.
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: third party application may use this network protocol as part of its feature. Filter is needed.
references:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
tags:
analytic_story:
- AgentTesla
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 30
context:
- Source:Endpoint
- Stage:Command And Control
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/agent_tesla/agent_tesla_ftp/sysmon.log
impact: 30
kill_chain_phases:
- Command & Control
message: a process $Image$ is having a FTP connection to $DestinationHostname$ in $Computer$
mitre_attack_id:
- T1071.003
- T1071
nist:
- DE.CM
observable:
- name: Computer
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Image
- DestinationPort
- DestinationPortName
- DestinationHostname
- SourceHostname
- SourcePort
- SourcePortName
- Protocol
- DestinationIp
- Computer
- user
risk_score: 9
security_domain: endpoint
@@ -1,15 +1,15 @@
name: Windows ISO LNK File Creation
id: d7c2c09b-9569-4a9e-a8b6-6a39a99c1d32
version: 1
date: '2022-03-29'
author: Michael Haag, Splunk
version: 2
date: '2022-09-19'
author: Michael Haag, Teoderick Contreras, Splunk
type: Hunting
datamodel:
- Endpoint
description: The following analytic identifies the use of a delivered ISO file that has been mounted and the afformention lnk or file opened within it. When the ISO file is opened, the files are saved in the %USER%\AppData\Local\Temp\<random folder name>\ path.
The analytic identifies .iso.lnk written to the path. The name of the ISO file is prepended.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\Microsoft\\Windows\\Recent\\*") Filesystem.file_name IN ("*.iso.lnk") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.dest
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\Microsoft\\Windows\\Recent\\*") Filesystem.file_name IN ("*.iso.lnk", "*.img.lnk", "*.vhd.lnk", "*vhdx.lnk") by Filesystem.file_create_time Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.dest
| `drop_dm_object_name(Filesystem)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
@@ -23,6 +23,7 @@ tags:
analytic_story:
- Spearphishing Attachments
- Brute Ratel C4
- AgentTesla
asset_type: Endpoint
cis20:
- CIS 3
@@ -0,0 +1,72 @@
name: Windows Mail Protocol In Non-Common Process Path
id: ac3311f5-661d-4e99-bd1f-3ec665b05441
version: 1
date: '2022-09-16'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies a possible windows application having a SMTP connection
in a non common installation path in windows operating system.This network protocol is being used by adversaries,
threat actors and malware like AgentTesla as a command and control communication to transfer its collected stolen information
like the desktop screenshots, browser information and system information of a targeted or compromised host.
search: '`sysmon` EventCode=3 NOT(Image IN("*\\program files*", "*\\thunderbird.exe","*\\outlook.exe"))
(DestinationPortName="smtp" OR DestinationPort=25 OR DestinationPort=587)
| stats count min(_time) as firstTime max(_time) as lastTime by Image DestinationPort DestinationPortName DestinationHostname
SourceHostname SourcePort SourcePortName Protocol DestinationIp Computer user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `windows_mail_protocol_in_non_common_process_path_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name and sysmon eventcode = 3 connection events from your endpoints.
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: third party application may use this network protocol as part of its feature. Filter is needed.
references:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
tags:
analytic_story:
- AgentTesla
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 30
context:
- Source:Endpoint
- Stage:Command And Control
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/agent_tesla/agent_tesla_smtp/sysmon.log
impact: 30
kill_chain_phases:
- Command & Control
message: a process $Image$ is having a SMTP connection to $DestinationHostname$ in $Computer$
mitre_attack_id:
- T1071.003
- T1071
nist:
- DE.CM
observable:
- name: Computer
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Image
- DestinationPort
- DestinationPortName
- DestinationHostname
- SourceHostname
- SourcePort
- SourcePortName
- Protocol
- DestinationIp
- Computer
- user
risk_score: 9
security_domain: endpoint
@@ -0,0 +1,63 @@
name: Windows Multi hop Proxy TOR Website Query
id: 4c2d198b-da58-48d7-ba27-9368732d0054
version: 1
date: '2022-09-16'
author: Teoderick Contreras, Splunk
type: Anomaly
datamodel:
- Endpoint
description: The following analytic identifies a dns query to a known TOR proxy website.
This technique was seen in several adversaries, threat actors and malware like AgentTesla
to To disguise the source of its malicious traffic. adversaries may chain together multiple proxies.
This Anomaly detection might be a good pivot for a process trying to download or use TOR proxies in a compromised host machine.
search: '`sysmon` EventCode=22 QueryName IN ("*.torproject.org", "www.theonionrouter.com")
| stats count min(_time) as firstTime max(_time) as lastTime by Image QueryName QueryStatus ProcessId Computer
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `windows_multi_hop_proxy_tor_website_query_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name and sysmon eventcode = 22 dns query events from your endpoints.
If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: third party application may use this proxies if allowed in production environment. Filter is needed.
references:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
tags:
analytic_story:
- AgentTesla
asset_type: Endpoint
cis20:
- CIS 3
- CIS 5
- CIS 16
confidence: 50
context:
- Source:Endpoint
- Stage:Command And Control
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/agent_tesla/agent_tesla_tor_dns_query/sysmon.log
impact: 50
kill_chain_phases:
- Command & Control
message: a process $Image$ is having a dns query in a tor domain $QueryName$ in $Computer$
mitre_attack_id:
- T1071.003
- T1071
nist:
- DE.CM
observable:
- name: Computer
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Image
- QueryName
- QueryStatus
- ProcessId
- Computer
risk_score: 25
security_domain: endpoint
@@ -1,7 +1,7 @@
name: Windows Phishing Recent ISO Exec Registry
id: cb38ee66-8ae5-47de-bd66-231c7bbc0b2c
version: 1
date: '2022-08-24'
version: 2
date: '2022-09-19'
author: Teoderick Contreras, Splunk
type: Hunting
datamodel:
@@ -10,7 +10,8 @@ description: The following hunting analytic identifies registry artifacts when a
As Microsoft makes changes to macro based document execution, adversaries have begun to utilize container based initial access based phishing campaigns to evade preventative controls.
Once the ISO is clicked or mounted it will create a registry artifact related to this event as a recent application executed or opened.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry
where Registry.registry_key_name= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RecentDocs\\.iso"
where Registry.registry_key_name= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RecentDocs\\.iso" OR
Registry.registry_key_name= "*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RecentDocs\\.img"
by Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_data Registry.action Registry.dest
| `drop_dm_object_name(Registry)`
| `security_content_ctime(firstTime)`
@@ -28,6 +29,7 @@ references:
tags:
analytic_story:
- Brute Ratel C4
- AgentTesla
asset_type: Endpoint
cis20:
- CIS 3
@@ -0,0 +1,13 @@
name: Windows File Transfer Protocol In Non-Common Process Path Unit Test
tests:
- name: Windows File Transfer Protocol In Non-Common Process Path
file: endpoint/windows_file_transfer_protocol_in_non_common_process_path.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/agent_tesla/agent_tesla_ftp/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows Mail Protocol In Non-Common Process Path Unit Test
tests:
- name: Windows Mail Protocol In Non-Common Process Path
file: endpoint/windows_mail_protocol_in_non_common_process_path.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/agent_tesla/agent_tesla_smtp/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true
@@ -0,0 +1,13 @@
name: Windows Multi-hop Proxy TOR Website Query Unit Test
tests:
- name: Windows Multi-hop Proxy TOR Website Query
file: endpoint/windows_multi_hop_proxy_tor_website_query.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/agent_tesla/agent_tesla_tor_dns_query/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
update_timestamp: true