From 6532c7369de73957f15fa82078482ec171006f3c Mon Sep 17 00:00:00 2001 From: tccontre Date: Tue, 29 Aug 2023 09:32:10 +0200 Subject: [PATCH] minor_fix_warzone --- stories/warzone_rat.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/stories/warzone_rat.yml b/stories/warzone_rat.yml index f7e8d26400..36c5c2f765 100644 --- a/stories/warzone_rat.yml +++ b/stories/warzone_rat.yml @@ -4,7 +4,7 @@ version: 1 date: '2023-07-26' author: Teoderick Contreras, Splunk description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities - that might related to warzone (ve maria) RAT. This analytic story looks for suspicious process execution, command-line activity, downloads, persistence, defense evasion and more. + that might related to warzone (Ave maria) RAT. This analytic story looks for suspicious process execution, command-line activity, downloads, persistence, defense evasion and more. narrative: Warzone RAT, also known as Ave Maria, is a sophisticated remote access trojan (RAT) that surfaced in January 2019. Originally offered as malware-as-a-service (MaaS), it rapidly gained notoriety and became one of the most prominent malware strains by 2020. Its exceptional capabilities in stealth and anti-analysis techniques make it a formidable threat in various campaigns, including those targeting sensitive geopolitical entities.