Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-04-05 13:56:44 -07:00
committed by GitHub
41 changed files with 41 additions and 0 deletions
@@ -30,6 +30,7 @@ references: []
tags:
analytic_story:
- Malicious PowerShell
- Hermetic Wiper
asset_type: Endpoint
cis20:
- CIS 3
@@ -26,6 +26,7 @@ tags:
analytic_story:
- Windows Privilege Escalation
- Unusual Processes
- Hermetic Wiper
asset_type: Endpoint
cis20:
- CIS 2
@@ -40,6 +40,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Hermetic Wiper
confidence: 80
context:
- Source:Endpoint
@@ -31,6 +31,7 @@ references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- Ingress Tool Transfer
- Log4Shell CVE-2021-44228
@@ -30,6 +30,7 @@ references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- HAFNIUM Group
- Ingress Tool Transfer
@@ -31,6 +31,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -37,6 +37,7 @@ references:
- https://github.com/BC-SECURITY/Empire
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 90
context:
@@ -34,6 +34,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 100
context:
@@ -38,6 +38,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -30,6 +30,7 @@ tags:
analytic_story:
- Windows Privilege Escalation
- Active Directory Kerberos Attacks
- Hermetic Wiper
asset_type: Endpoint
cis20:
- CIS 8
@@ -30,6 +30,7 @@ references:
- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72
tags:
analytic_story:
- Hermetic Wiper
- Log4Shell CVE-2021-44228
asset_type: Endpoint
confidence: 50
@@ -28,6 +28,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -40,6 +40,7 @@ references:
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- NOBELIUM Group
- WhisperGate
@@ -26,6 +26,7 @@ known_false_positives: These characters might be legitimately on the command-lin
references: []
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
asset_type: Endpoint
cis20:
@@ -39,6 +39,7 @@ references:
tags:
analytic_story:
- Windows Privilege Escalation
- Hermetic Wiper
confidence: 70
context:
- Source:Endpoint
@@ -28,6 +28,7 @@ references: []
tags:
analytic_story:
- Windows Privilege Escalation
- Hermetic Wiper
asset_type: Endpoint
cis20:
- CIS 8
@@ -37,6 +37,7 @@ references:
- https://attack.mitre.org/techniques/T1543/003/
tags:
analytic_story:
- Hermetic Wiper
- Active Directory Lateral Movement
- Malicious PowerShell
confidence: 50
@@ -49,6 +49,7 @@ references:
- https://hurricanelabs.com/splunk-tutorials/how-to-use-powershell-transcription-logs-in-splunk/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 100
context:
@@ -36,6 +36,7 @@ references:
- https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
- HAFNIUM Group
@@ -32,6 +32,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 70
context:
@@ -22,6 +22,7 @@ references:
- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- Ransomware
context:
@@ -24,6 +24,7 @@ references:
- https://threadreaderapp.com/thread/1423361119926816776.html
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- Ransomware
confidence: 50
@@ -35,6 +35,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 80
context:
@@ -34,6 +34,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 80
context:
@@ -36,6 +36,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 80
context:
@@ -27,6 +27,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 80
context:
@@ -27,6 +27,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 80
context:
@@ -28,6 +28,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Ransomware
- Malicious PowerShell
confidence: 80
@@ -29,6 +29,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 80
context:
@@ -40,6 +40,7 @@ tags:
- Suspicious Windows Registry Activities
- Cloud Federated Credential Abuse
- Windows Registry Abuse
- Hermetic Wiper
cis20:
- CIS 8
confidence: 95
@@ -31,6 +31,7 @@ references:
tags:
analytic_story:
- Windows Privilege Escalation
- Hermetic Wiper
confidence: 50
context:
- Source:Endpoint
@@ -32,6 +32,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
confidence: 90
context:
- Source:Endpoint
@@ -25,6 +25,7 @@ known_false_positives: Administrators may attempt to change the default executio
references: []
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
- Credential Dumping
- HAFNIUM Group
@@ -39,6 +39,7 @@ tags:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Windows Registry Abuse
- Hermetic Wiper
confidence: 100
context:
- Source:Endpoint
@@ -35,6 +35,7 @@ references:
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 70
context:
@@ -35,6 +35,7 @@ references:
- https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do
tags:
analytic_story:
- Hermetic Wiper
- HAFNIUM Group
- ProxyShell
confidence: 80
@@ -26,6 +26,7 @@ references:
- https://in.security/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/
tags:
analytic_story:
- Hermetic Wiper
- Malicious PowerShell
confidence: 100
context:
@@ -32,6 +32,7 @@ known_false_positives: None at this time
references: []
tags:
analytic_story:
- Hermetic Wiper
- 'Emotet Malware DHS Report TA18-201A '
- Suspicious Emails
asset_type: Endpoint
@@ -29,6 +29,7 @@ known_false_positives: None identified
references: []
tags:
analytic_story:
- Hermetic Wiper
- 'Emotet Malware DHS Report TA18-201A '
- Suspicious Emails
asset_type: Endpoint
@@ -28,6 +28,7 @@ references: []
tags:
analytic_story:
- Windows Privilege Escalation
- Hermetic Wiper
asset_type: Endpoint
cis20:
- CIS 5
@@ -32,6 +32,7 @@ tags:
analytic_story:
- Windows Persistence Techniques
- Windows Privilege Escalation
- Hermetic Wiper
asset_type: Endpoint
confidence: 100
context: