diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 0cf679f954..b47cabc958 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -30,6 +30,7 @@ references: tags: analytic_story: - Ransomware + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index 7cad91b604..13fc33529a 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -32,6 +32,7 @@ tags: analytic_story: - Ransomware - Revil Ransomware + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/anomalous_usage_of_7zip.yml b/detections/endpoint/anomalous_usage_of_7zip.yml index 8d411a6c1b..3be0e282d8 100644 --- a/detections/endpoint/anomalous_usage_of_7zip.yml +++ b/detections/endpoint/anomalous_usage_of_7zip.yml @@ -1,7 +1,7 @@ name: Anomalous usage of 7zip id: 9364ee8e-a39a-11eb-8f1d-acde48001122 version: 1 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Teoderick Contreras, Splunk status: production type: Anomaly @@ -31,8 +31,9 @@ references: - https://thedfirreport.com/2021/01/31/bazar-no-ryuk/ tags: analytic_story: - - Cobalt Strike - NOBELIUM Group + - BlackByte Ransomware + - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint confidence: 80 diff --git a/detections/endpoint/cmd_echo_pipe___escalation.yml b/detections/endpoint/cmd_echo_pipe___escalation.yml index 93f66d6b34..de98f5e880 100644 --- a/detections/endpoint/cmd_echo_pipe___escalation.yml +++ b/detections/endpoint/cmd_echo_pipe___escalation.yml @@ -1,7 +1,7 @@ name: CMD Echo Pipe - Escalation id: eb277ba0-b96b-11eb-b00e-acde48001122 version: 2 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -29,6 +29,7 @@ references: - https://github.com/rapid7/meterpreter/blob/master/source/extensions/priv/server/elevate/namedpipe.c tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/cobalt_strike_named_pipes.yml b/detections/endpoint/cobalt_strike_named_pipes.yml index 7cdf14cf0b..a40f1bc33b 100644 --- a/detections/endpoint/cobalt_strike_named_pipes.yml +++ b/detections/endpoint/cobalt_strike_named_pipes.yml @@ -1,7 +1,7 @@ name: Cobalt Strike Named Pipes id: 5876d429-0240-4709-8b93-ea8330b411b5 version: 2 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -41,11 +41,12 @@ references: - https://www.mandiant.com/resources/shining-a-light-on-darkside-ransomware-operations tags: analytic_story: - - LockBit Ransomware - - Graceful Wipe Out Attack - - Cobalt Strike - - DarkSide Ransomware - Trickbot + - DarkSide Ransomware + - Cobalt Strike + - BlackByte Ransomware + - Graceful Wipe Out Attack + - LockBit Ransomware asset_type: Endpoint confidence: 90 impact: 80 diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 62ca63a1c3..9d28f395e7 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -1,7 +1,7 @@ name: Detect Exchange Web Shell id: 8c14eeee-2af1-4a4b-bda8-228da0f4862a version: 4 -date: '2022-09-30' +date: '2023-07-10' author: Michael Haag, Shannon Davis, David Dorsey, Splunk status: production type: TTP @@ -52,10 +52,11 @@ references: - https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do tags: analytic_story: - - HAFNIUM Group + - ProxyNotShell - ProxyShell - CISA AA22-257A - - ProxyNotShell + - HAFNIUM Group + - BlackByte Ransomware asset_type: Endpoint confidence: 90 impact: 90 diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 1ae1f62a99..79b2c07045 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -43,6 +43,7 @@ tags: - Sandworm Tools - Volt Typhoon - IcedID + - BlackByte Ransomware asset_type: Endpoint confidence: 70 impact: 50 diff --git a/detections/endpoint/detect_regsvr32_application_control_bypass.yml b/detections/endpoint/detect_regsvr32_application_control_bypass.yml index 751f1e6bf7..471969d537 100644 --- a/detections/endpoint/detect_regsvr32_application_control_bypass.yml +++ b/detections/endpoint/detect_regsvr32_application_control_bypass.yml @@ -1,7 +1,7 @@ name: Detect Regsvr32 Application Control Bypass id: 070e9b80-6252-11eb-ae93-0242ac130002 version: 2 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -37,10 +37,11 @@ references: - https://support.microsoft.com/en-us/topic/how-to-use-the-regsvr32-tool-and-troubleshoot-regsvr32-error-messages-a98d960a-7392-e6fe-d90a-3f4e0cb543e5 tags: analytic_story: - - Cobalt Strike - Living Off The Land - - Suspicious Regsvr32 Activity + - Cobalt Strike + - BlackByte Ransomware - Graceful Wipe Out Attack + - Suspicious Regsvr32 Activity asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/detect_renamed_psexec.yml b/detections/endpoint/detect_renamed_psexec.yml index a7c8026c79..2c3fcf91b7 100644 --- a/detections/endpoint/detect_renamed_psexec.yml +++ b/detections/endpoint/detect_renamed_psexec.yml @@ -38,6 +38,7 @@ tags: - Active Directory Lateral Movement - CISA AA22-320A - Sandworm Tools + - BlackByte Ransomware asset_type: Endpoint confidence: 90 impact: 30 diff --git a/detections/endpoint/detect_webshell_exploit_behavior.yml b/detections/endpoint/detect_webshell_exploit_behavior.yml index dc463f27d0..bede99f459 100644 --- a/detections/endpoint/detect_webshell_exploit_behavior.yml +++ b/detections/endpoint/detect_webshell_exploit_behavior.yml @@ -1,82 +1,88 @@ -name: Detect Webshell Exploit Behavior -id: 22597426-6dbd-49bd-bcdc-4ec19857192f -version: 2 -date: '2023-04-26' -author: Steven Dick -status: production -type: TTP -description: This search is used to detect the abuse of web applications by adversaries. Adversaries may install a backdoor or script onto web servers by exploiting known vulnerabilities or misconfigruations. Web shells are used to establish persistent access to systems and provide a set of executable functions or a command-line interface on the system hosting the Web server. -data_source: -- Sysmon Event ID 1 -search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time) as firstTime from datamodel=Endpoint.Processes -where (Processes.process_name IN ("arp.exe","at.exe","bash.exe","bitsadmin.exe","certutil.exe","cmd.exe","cscript.exe", -"dsget.exe","dsquery.exe","find.exe","findstr.exe","fsutil.exe","hostname.exe","ipconfig.exe","ksh.exe","nbstat.exe", -"net.exe","net1.exe","netdom.exe","netsh.exe","netstat.exe","nltest.exe","nslookup.exe","ntdsutil.exe","pathping.exe", -"ping.exe","powershell.exe","pwsh.exe","qprocess.exe","query.exe","qwinsta.exe","reg.exe","rundll32.exe","sc.exe", -"scrcons.exe","schtasks.exe","sh.exe","systeminfo.exe","tasklist.exe","tracert.exe","ver.exe","vssadmin.exe", -"wevtutil.exe","whoami.exe","wmic.exe","wscript.exe","wusa.exe","zsh.exe") -AND Processes.parent_process_name IN ("w3wp.exe", "http*.exe", "nginx*.exe", "php*.exe", "php-cgi*.exe","tomcat*.exe")) -by Processes.dest,Processes.user,Processes.parent_process,Processes.parent_process_name,Processes.process,Processes.process_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_webshell_exploit_behavior_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information - on process that includes the full command line of the process being launched on - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -known_false_positives: Legitimate OS functions called by vendor applications, baseline the environment and filter before enabling. Recommend throttle by dest/process_name -references: -- https://attack.mitre.org/techniques/T1505/003/ -- https://github.com/nsacyber/Mitigating-Web-Shells -- https://www.hackingarticles.in/multiple-ways-to-exploit-tomcat-manager/ -tags: - analytic_story: - - ProxyShell - - ProxyNotShell - - HAFNIUM Group - - CISA AA22-257A - - CISA AA22-264A - asset_type: Endpoint - confidence: 80 - impact: 100 - message: Webshell Exploit Behavior - $parent_process_name$ spawned $process_name$ on $dest$. - mitre_attack_id: - - T1505 - - T1505.003 - observable: - - name: user - type: User - role: - - Victim - - name: dest - type: Endpoint - role: - - Victim - - name: process_name - type: Process - role: - - Attacker - product: - - Splunk Enterprise - - Splunk Enterprise Security - - Splunk Cloud - required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process - - Processes.parent_process_name - - Processes.process - - Processes.process_name - risk_score: 80 - security_domain: endpoint - supported_tas: - - Splunk_TA_microsoft_sysmon -tests: -- name: True Positive Test - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/generic_webshell_exploit/generic_webshell_exploit.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog +name: Detect Webshell Exploit Behavior +id: 22597426-6dbd-49bd-bcdc-4ec19857192f +version: 2 +date: '2023-07-10' +author: Steven Dick +status: production +type: TTP +description: This search is used to detect the abuse of web applications by adversaries. + Adversaries may install a backdoor or script onto web servers by exploiting known + vulnerabilities or misconfigruations. Web shells are used to establish persistent + access to systems and provide a set of executable functions or a command-line interface + on the system hosting the Web server. +data_source: +- Sysmon Event ID 1 +search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time) + as firstTime from datamodel=Endpoint.Processes where (Processes.process_name IN + ("arp.exe","at.exe","bash.exe","bitsadmin.exe","certutil.exe","cmd.exe","cscript.exe", + "dsget.exe","dsquery.exe","find.exe","findstr.exe","fsutil.exe","hostname.exe","ipconfig.exe","ksh.exe","nbstat.exe", + "net.exe","net1.exe","netdom.exe","netsh.exe","netstat.exe","nltest.exe","nslookup.exe","ntdsutil.exe","pathping.exe", + "ping.exe","powershell.exe","pwsh.exe","qprocess.exe","query.exe","qwinsta.exe","reg.exe","rundll32.exe","sc.exe", + "scrcons.exe","schtasks.exe","sh.exe","systeminfo.exe","tasklist.exe","tracert.exe","ver.exe","vssadmin.exe", + "wevtutil.exe","whoami.exe","wmic.exe","wscript.exe","wusa.exe","zsh.exe") AND Processes.parent_process_name + IN ("w3wp.exe", "http*.exe", "nginx*.exe", "php*.exe", "php-cgi*.exe","tomcat*.exe")) + by Processes.dest,Processes.user,Processes.parent_process,Processes.parent_process_name,Processes.process,Processes.process_name + | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `detect_webshell_exploit_behavior_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that includes the full command line of the process being launched on + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: Legitimate OS functions called by vendor applications, baseline + the environment and filter before enabling. Recommend throttle by dest/process_name +references: +- https://attack.mitre.org/techniques/T1505/003/ +- https://github.com/nsacyber/Mitigating-Web-Shells +- https://www.hackingarticles.in/multiple-ways-to-exploit-tomcat-manager/ +tags: + analytic_story: + - ProxyNotShell + - ProxyShell + - CISA AA22-257A + - HAFNIUM Group + - BlackByte Ransomware + - CISA AA22-264A + asset_type: Endpoint + confidence: 80 + impact: 100 + message: Webshell Exploit Behavior - $parent_process_name$ spawned $process_name$ + on $dest$. + mitre_attack_id: + - T1505 + - T1505.003 + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Endpoint + role: + - Victim + - name: process_name + type: Process + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process + - Processes.parent_process_name + - Processes.process + - Processes.process_name + risk_score: 80 + security_domain: endpoint + supported_tas: + - Splunk_TA_microsoft_sysmon +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/generic_webshell_exploit/generic_webshell_exploit.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/detections/endpoint/disabling_firewall_with_netsh.yml b/detections/endpoint/disabling_firewall_with_netsh.yml index 43e2530b6a..01676b435f 100644 --- a/detections/endpoint/disabling_firewall_with_netsh.yml +++ b/detections/endpoint/disabling_firewall_with_netsh.yml @@ -28,6 +28,7 @@ references: tags: analytic_story: - Windows Defense Evasion Tactics + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml index a9f50d7c33..d40cf5bd4c 100644 --- a/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/dllhost_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: DLLHost with no Command Line Arguments with Network id: f1c07594-a141-11eb-8407-acde48001122 version: 4 -date: '2023-06-13' +date: '2023-07-10' author: Steven Dick, Michael Haag, Splunk status: experimental type: TTP @@ -33,6 +33,7 @@ references: - https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/ tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml b/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml index cb79dd95fe..c6482b97fe 100644 --- a/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml +++ b/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml @@ -29,6 +29,7 @@ tags: analytic_story: - Data Destruction - WhisperGate + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/excessive_service_stop_attempt.yml b/detections/endpoint/excessive_service_stop_attempt.yml index dd74f40bdb..4a7d29a7c2 100644 --- a/detections/endpoint/excessive_service_stop_attempt.yml +++ b/detections/endpoint/excessive_service_stop_attempt.yml @@ -31,6 +31,7 @@ tags: analytic_story: - XMRig - Ransomware + - BlackByte Ransomware asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/exchange_powershell_abuse_via_ssrf.yml b/detections/endpoint/exchange_powershell_abuse_via_ssrf.yml index 3d78b9ece7..74d8e3cad2 100644 --- a/detections/endpoint/exchange_powershell_abuse_via_ssrf.yml +++ b/detections/endpoint/exchange_powershell_abuse_via_ssrf.yml @@ -1,7 +1,7 @@ name: Exchange PowerShell Abuse via SSRF id: 29228ab4-0762-11ec-94aa-acde48001122 version: 2 -date: '2022-10-02' +date: '2023-07-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -37,6 +37,7 @@ references: tags: analytic_story: - ProxyShell + - BlackByte Ransomware - ProxyNotShell asset_type: Endpoint confidence: 100 diff --git a/detections/endpoint/exchange_powershell_module_usage.yml b/detections/endpoint/exchange_powershell_module_usage.yml index e2eb808731..b8a8500652 100644 --- a/detections/endpoint/exchange_powershell_module_usage.yml +++ b/detections/endpoint/exchange_powershell_module_usage.yml @@ -1,7 +1,7 @@ name: Exchange PowerShell Module Usage id: 2d10095e-05ae-11ec-8fdf-acde48001122 version: 5 -date: '2022-11-21' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -51,10 +51,11 @@ references: - https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/ tags: analytic_story: - - ProxyShell - - CISA AA22-264A - ProxyNotShell - CISA AA22-277A + - ProxyShell + - BlackByte Ransomware + - CISA AA22-264A asset_type: Endpoint confidence: 80 impact: 40 diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index 9c18f08f8b..59ed5543bc 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -60,6 +60,7 @@ tags: - Chaos Ransomware - Trickbot - Amadey + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 40 diff --git a/detections/endpoint/firewall_allowed_program_enable.yml b/detections/endpoint/firewall_allowed_program_enable.yml index d3091c0f9e..41cb565451 100644 --- a/detections/endpoint/firewall_allowed_program_enable.yml +++ b/detections/endpoint/firewall_allowed_program_enable.yml @@ -33,6 +33,7 @@ tags: analytic_story: - Windows Defense Evasion Tactics - Azorult + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml index 608c640c5a..ea56bc7f6d 100644 --- a/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/gpupdate_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: GPUpdate with no Command Line Arguments with Network id: 2c853856-a140-11eb-a5b5-acde48001122 version: 2 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -33,6 +33,7 @@ references: - https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/ tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/high_process_termination_frequency.yml b/detections/endpoint/high_process_termination_frequency.yml index 6f80bd4062..de642be9aa 100644 --- a/detections/endpoint/high_process_termination_frequency.yml +++ b/detections/endpoint/high_process_termination_frequency.yml @@ -27,6 +27,7 @@ tags: analytic_story: - Clop Ransomware - LockBit Ransomware + - BlackByte Ransomware asset_type: Endpoint confidence: 80 impact: 90 diff --git a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml index fd80d104f1..15514c9543 100644 --- a/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml +++ b/detections/endpoint/ms_exchange_mailbox_replication_service_writing_active_server_pages.yml @@ -1,7 +1,7 @@ name: MS Exchange Mailbox Replication service writing Active Server Pages id: 985f322c-57a5-11ec-b9ac-acde48001122 version: 1 -date: '2021-12-07' +date: '2023-07-10' author: Michael Haag, Splunk status: experimental type: TTP @@ -52,6 +52,7 @@ tags: analytic_story: - ProxyShell - Ransomware + - BlackByte Ransomware asset_type: Endpoint confidence: 90 impact: 90 diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml index a75912c59c..cc54072880 100644 --- a/detections/endpoint/ping_sleep_batch_command.yml +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -33,6 +33,7 @@ tags: analytic_story: - Data Destruction - WhisperGate + - BlackByte Ransomware asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 911a9b51d0..39d59f14ac 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -67,6 +67,7 @@ tags: - AsyncRAT - Amadey - Sneaky Active Directory Persistence Tricks + - BlackByte Ransomware asset_type: Endpoint confidence: 95 impact: 80 diff --git a/detections/endpoint/resize_shadowstorage_volume.yml b/detections/endpoint/resize_shadowstorage_volume.yml index ec5ab5503e..78d5d553da 100644 --- a/detections/endpoint/resize_shadowstorage_volume.yml +++ b/detections/endpoint/resize_shadowstorage_volume.yml @@ -37,6 +37,7 @@ references: tags: analytic_story: - Clop Ransomware + - BlackByte Ransomware asset_type: Endpoint confidence: 90 impact: 80 diff --git a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index 6f2ff8fb7f..444db9572a 100644 --- a/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -1,7 +1,7 @@ name: Rundll32 with no Command Line Arguments with Network id: 35307032-a12d-11eb-835f-acde48001122 version: 4 -date: '2023-06-13' +date: '2023-07-10' author: Steven Dick, Michael Haag, Splunk status: production type: TTP @@ -40,9 +40,10 @@ references: - https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - - Cobalt Strike - - PrintNightmare CVE-2021-34527 - Suspicious Rundll32 Activity + - Cobalt Strike + - BlackByte Ransomware + - PrintNightmare CVE-2021-34527 - Graceful Wipe Out Attack asset_type: Endpoint confidence: 100 diff --git a/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml b/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml index c5225623e9..6282e5a9f7 100644 --- a/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml +++ b/detections/endpoint/searchprotocolhost_with_no_command_line_with_network.yml @@ -1,7 +1,7 @@ name: SearchProtocolHost with no Command Line with Network id: b690df8c-a145-11eb-a38b-acde48001122 version: 3 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -32,6 +32,7 @@ references: - https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/services_escalate_exe.yml b/detections/endpoint/services_escalate_exe.yml index 76028dd4b5..4e7bb63c84 100644 --- a/detections/endpoint/services_escalate_exe.yml +++ b/detections/endpoint/services_escalate_exe.yml @@ -1,7 +1,7 @@ name: Services Escalate Exe id: c448488c-b7ec-11eb-8253-acde48001122 version: 1 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -35,6 +35,7 @@ references: - https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/index.htm#cshid=1085 tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml index 291bbba2dc..ec10fa68a3 100644 --- a/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_dllhost_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious DLLHost no Command Line Arguments id: ff61e98c-0337-4593-a78f-72a676c56f26 version: 4 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -30,6 +30,7 @@ references: - https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/ tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/suspicious_driver_loaded_path.yml b/detections/endpoint/suspicious_driver_loaded_path.yml index 5efd1721a2..a963f6ed94 100644 --- a/detections/endpoint/suspicious_driver_loaded_path.yml +++ b/detections/endpoint/suspicious_driver_loaded_path.yml @@ -33,6 +33,7 @@ tags: - XMRig - CISA AA22-320A - AgentTesla + - BlackByte Ransomware asset_type: Endpoint confidence: 90 impact: 70 diff --git a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml index a965271e52..29a48aa774 100644 --- a/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_gpupdate_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious GPUpdate no Command Line Arguments id: f308490a-473a-40ef-ae64-dd7a6eba284a version: 3 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -29,6 +29,7 @@ references: - https://www.cobaltstrike.com/blog/learn-pipe-fitting-for-all-of-your-offense-projects/ tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index 2b39dd5277..2b6dcd41d1 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -1,7 +1,7 @@ name: Suspicious microsoft workflow compiler rename id: f0db4464-55d9-11eb-ae93-0242ac130002 version: 4 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: Hunting @@ -33,10 +33,11 @@ references: tags: analytic_story: - Masquerading - Rename System Utilities - - Trusted Developer Utilities Proxy Execution - - Graceful Wipe Out Attack - Living Off The Land - Cobalt Strike + - Trusted Developer Utilities Proxy Execution + - BlackByte Ransomware + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 90 impact: 70 diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index 5cf8df0b33..b077b803e7 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -1,7 +1,7 @@ name: Suspicious msbuild path id: f5198224-551c-11eb-ae93-0242ac130002 version: 3 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -32,11 +32,12 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md tags: analytic_story: - - Masquerading - Rename System Utilities - - Graceful Wipe Out Attack - - Living Off The Land - Trusted Developer Utilities Proxy Execution MSBuild + - Masquerading - Rename System Utilities + - Living Off The Land - Cobalt Strike + - BlackByte Ransomware + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 5f0503e8e2..990348ae6e 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -1,7 +1,7 @@ name: Suspicious MSBuild Rename id: 4006adac-5937-11eb-ae93-0242ac130002 version: 3 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: Hunting @@ -30,11 +30,12 @@ references: - https://github.com/infosecn1nja/MaliciousMacroMSBuild/ tags: analytic_story: - - Masquerading - Rename System Utilities - - Graceful Wipe Out Attack - - Living Off The Land - Trusted Developer Utilities Proxy Execution MSBuild + - Masquerading - Rename System Utilities + - Living Off The Land - Cobalt Strike + - BlackByte Ransomware + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 90 impact: 70 diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 8c698e04df..fa4177a4db 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -61,6 +61,7 @@ tags: - Chaos Ransomware - Trickbot - Amadey + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 70 diff --git a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml index e5c0fbd983..e672e78c55 100644 --- a/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 no Command Line Arguments id: e451bd16-e4c5-4109-8eb1-c4c6ecf048b4 version: 3 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -32,9 +32,10 @@ references: - https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - - Cobalt Strike - - PrintNightmare CVE-2021-34527 - Suspicious Rundll32 Activity + - Cobalt Strike + - BlackByte Ransomware + - PrintNightmare CVE-2021-34527 - Graceful Wipe Out Attack asset_type: Endpoint confidence: 70 diff --git a/detections/endpoint/suspicious_rundll32_startw.yml b/detections/endpoint/suspicious_rundll32_startw.yml index 192ee5efa8..e1691ee157 100644 --- a/detections/endpoint/suspicious_rundll32_startw.yml +++ b/detections/endpoint/suspicious_rundll32_startw.yml @@ -1,7 +1,7 @@ name: Suspicious Rundll32 StartW id: 9319dda5-73f2-4d43-a85a-67ce961bddb7 version: 3 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -37,10 +37,11 @@ references: - https://bohops.com/2018/02/26/leveraging-inf-sct-fetch-execute-techniques-for-bypass-evasion-persistence/ tags: analytic_story: - - Cobalt Strike - - Suspicious Rundll32 Activity - - Graceful Wipe Out Attack - Trickbot + - Suspicious Rundll32 Activity + - Cobalt Strike + - BlackByte Ransomware + - Graceful Wipe Out Attack asset_type: Endpoint confidence: 50 impact: 70 diff --git a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml index 9c1cd51772..d1ed4de967 100644 --- a/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml +++ b/detections/endpoint/suspicious_searchprotocolhost_no_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious SearchProtocolHost no Command Line Arguments id: f52d2db8-31f9-4aa7-a176-25779effe55c version: 3 -date: '2023-06-13' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -30,6 +30,7 @@ references: - https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc tags: analytic_story: + - BlackByte Ransomware - Cobalt Strike - Graceful Wipe Out Attack asset_type: Endpoint diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index 76d21f86e5..36bb5e4074 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -1,7 +1,7 @@ name: W3WP Spawning Shell id: 0f03423c-7c6a-11eb-bc47-acde48001122 version: 2 -date: '2023-04-14' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: TTP @@ -36,13 +36,14 @@ references: - https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do tags: analytic_story: - - HAFNIUM Group - - CISA AA22-264A - - Hermetic Wiper - ProxyNotShell - - ProxyShell - - CISA AA22-257A - Data Destruction + - ProxyShell + - Hermetic Wiper + - CISA AA22-257A + - HAFNIUM Group + - BlackByte Ransomware + - CISA AA22-264A asset_type: Endpoint confidence: 80 cve: diff --git a/detections/endpoint/windows_driver_load_non_standard_path.yml b/detections/endpoint/windows_driver_load_non_standard_path.yml index 067697a6ab..84653c942e 100644 --- a/detections/endpoint/windows_driver_load_non_standard_path.yml +++ b/detections/endpoint/windows_driver_load_non_standard_path.yml @@ -34,6 +34,7 @@ tags: - Windows Drivers - CISA AA22-320A - AgentTesla + - BlackByte Ransomware asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/windows_drivers_loaded_by_signature.yml b/detections/endpoint/windows_drivers_loaded_by_signature.yml index 695a8c72c3..8c66603eb4 100644 --- a/detections/endpoint/windows_drivers_loaded_by_signature.yml +++ b/detections/endpoint/windows_drivers_loaded_by_signature.yml @@ -33,6 +33,7 @@ tags: - Windows Drivers - CISA AA22-320A - AgentTesla + - BlackByte Ransomware asset_type: Endpoint confidence: 70 impact: 60 diff --git a/detections/endpoint/windows_modify_registry_enablelinkedconnections.yml b/detections/endpoint/windows_modify_registry_enablelinkedconnections.yml new file mode 100644 index 0000000000..84e59a722e --- /dev/null +++ b/detections/endpoint/windows_modify_registry_enablelinkedconnections.yml @@ -0,0 +1,67 @@ +name: Windows Modify Registry EnableLinkedConnections +id: 93048164-3358-4af0-8680-aa5f38440516 +version: 1 +date: '2023-07-10' +author: Teoderick Contreras, Splunk +status: production +type: TTP +data_source: +- Sysmon EventID 12 +- Sysmon EventID 13 +- Sysmon EventID 14 +description: The following analytic identifies a suspicious registry modification of Windows linked connection configuration. + This technique was being abused by several adversaries, malware like BlackByte ransomware to enable the linked connections feature, + that allows network shares to be accessed using both standard and administrator-level privileges simultaneously. + By default, Windows does not enable this feature to enhance security. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + WHERE (Registry.registry_path= "*\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLinkedConnections" Registry.registry_value_data = "0x00000001") + BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid + | `drop_dm_object_name(Registry)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_modify_registry_enablelinkedconnections_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: Administrators may enable or disable this feature that may + cause some false positive. +references: +- https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/ +tags: + analytic_story: + - BlackByte Ransomware + asset_type: endpoint + atomic_guid: + - 4f4e2f9f-6209-4fcf-9b15-3b7455706f5b + confidence: 70 + impact: 70 + message: A registry modification in Windows EnableLinkedConnections configuration on $dest$ + mitre_attack_id: + - T1112 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + risk_score: 49 + required_fields: + - _time + - Registry.registry_key_name + - Registry.registry_path + - Registry.user + - Registry.dest + - Registry.registry_value_name + - Registry.action + - Registry.registry_value_data + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/blackbyte/enablelinkedconnections/blackbyte_sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/detections/endpoint/windows_modify_registry_longpathsenabled.yml b/detections/endpoint/windows_modify_registry_longpathsenabled.yml new file mode 100644 index 0000000000..2a860cd88b --- /dev/null +++ b/detections/endpoint/windows_modify_registry_longpathsenabled.yml @@ -0,0 +1,67 @@ +name: Windows Modify Registry LongPathsEnabled +id: 36f9626c-4272-4808-aadd-267acce681c0 +version: 1 +date: '2023-07-10' +author: Teoderick Contreras, Splunk +status: production +type: Anomaly +data_source: +- Sysmon EventID 12 +- Sysmon EventID 13 +- Sysmon EventID 14 +description: The following analytic identifies a suspicious registry modification of Windows long path enable configuration. + This technique was being abused by several adversaries, malware like BlackByte to enable long file path support in the operating system. + By default, Windows has a limitation on the maximum length of a file path, which is set to 260 characters. + Enabling the LongPathsEnabled setting allows you to work with file paths longer than 260 characters. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry + WHERE (Registry.registry_path= "*\\CurrentControlSet\\Control\\FileSystem\\LongPathsEnabled" Registry.registry_value_data = "0x00000001") + BY _time span=1h Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data Registry.process_guid + | `drop_dm_object_name(Registry)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `windows_modify_registry_longpathsenabled_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure + that this registry was included in your config files ex. sysmon config to be monitored. +known_false_positives: Administrators may enable or disable this feature that may + cause some false positive. +references: +- https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/ +tags: + analytic_story: + - BlackByte Ransomware + asset_type: endpoint + atomic_guid: + - 4f4e2f9f-6209-4fcf-9b15-3b7455706f5b + confidence: 40 + impact: 40 + message: A registry modification in Windows LongPathEnable configuration on $dest$ + mitre_attack_id: + - T1112 + observable: + - name: dest + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + risk_score: 16 + required_fields: + - _time + - Registry.registry_key_name + - Registry.registry_path + - Registry.user + - Registry.dest + - Registry.registry_value_name + - Registry.action + - Registry.registry_value_data + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/blackbyte/longpathsenabled/longpath_sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog diff --git a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml index bc176d1046..0b93e06312 100644 --- a/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml +++ b/detections/endpoint/windows_msexchange_management_mailbox_cmdlet_usage.yml @@ -1,7 +1,7 @@ name: Windows MSExchange Management Mailbox Cmdlet Usage id: 396de86f-25e7-4b0e-be09-a330be35249d version: 1 -date: '2022-11-21' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: Anomaly @@ -26,6 +26,7 @@ references: tags: analytic_story: - ProxyShell + - BlackByte Ransomware - ProxyNotShell asset_type: Endpoint confidence: 80 diff --git a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml index 0a52ba3dda..6e41f44515 100644 --- a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml +++ b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml @@ -32,6 +32,7 @@ tags: - Data Destruction - Hermetic Wiper - Caddy Wiper + - BlackByte Ransomware asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml index 613c5628dc..e9ddffbcac 100644 --- a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml +++ b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml @@ -35,6 +35,7 @@ tags: - Data Destruction - Hermetic Wiper - Caddy Wiper + - BlackByte Ransomware asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/windows_rdp_connection_successful.yml b/detections/endpoint/windows_rdp_connection_successful.yml index 24620bea14..1f7e45616f 100644 --- a/detections/endpoint/windows_rdp_connection_successful.yml +++ b/detections/endpoint/windows_rdp_connection_successful.yml @@ -20,6 +20,7 @@ references: tags: analytic_story: - Active Directory Lateral Movement + - BlackByte Ransomware asset_type: Endpoint atomic_guid: [] confidence: 50 diff --git a/detections/endpoint/windows_vulnerable_driver_loaded.yml b/detections/endpoint/windows_vulnerable_driver_loaded.yml index cd5337c70b..3ac76361ea 100644 --- a/detections/endpoint/windows_vulnerable_driver_loaded.yml +++ b/detections/endpoint/windows_vulnerable_driver_loaded.yml @@ -45,6 +45,7 @@ references: tags: analytic_story: - Windows Drivers + - BlackByte Ransomware asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/web/proxyshell_proxynotshell_behavior_detected.yml b/detections/web/proxyshell_proxynotshell_behavior_detected.yml index 9670242bc1..e62809b2a9 100644 --- a/detections/web/proxyshell_proxynotshell_behavior_detected.yml +++ b/detections/web/proxyshell_proxynotshell_behavior_detected.yml @@ -1,7 +1,7 @@ name: ProxyShell ProxyNotShell Behavior Detected id: c32fab32-6aaf-492d-bfaf-acbed8e50cdf version: 1 -date: '2022-10-03' +date: '2023-07-10' author: Michael Haag, Splunk status: production type: Correlation @@ -42,6 +42,7 @@ references: tags: analytic_story: - ProxyShell + - BlackByte Ransomware - ProxyNotShell asset_type: Web Server confidence: 90 diff --git a/detections/web/windows_exchange_autodiscover_ssrf_abuse.yml b/detections/web/windows_exchange_autodiscover_ssrf_abuse.yml index 7c2ac80407..9e30e6e3ea 100644 --- a/detections/web/windows_exchange_autodiscover_ssrf_abuse.yml +++ b/detections/web/windows_exchange_autodiscover_ssrf_abuse.yml @@ -1,7 +1,7 @@ name: Windows Exchange Autodiscover SSRF Abuse id: d436f9e7-0ee7-4a47-864b-6dea2c4e2752 version: 1 -date: '2022-10-03' +date: '2023-07-10' author: Michael Haag, Nathaniel Stearns, Splunk status: production type: TTP @@ -40,6 +40,7 @@ references: tags: analytic_story: - ProxyShell + - BlackByte Ransomware - ProxyNotShell asset_type: Web server confidence: 80 diff --git a/stories/blackbyte_ransomware.yml b/stories/blackbyte_ransomware.yml new file mode 100644 index 0000000000..452751a363 --- /dev/null +++ b/stories/blackbyte_ransomware.yml @@ -0,0 +1,26 @@ +name: BlackByte Ransomware +id: b18259ac-0746-45d7-bd1f-81d65274a80b +version: 1 +date: '2023-07-10' +author: Teoderick Contreras, Splunk +description: Leverage searches that allow you to detect and investigate unusual activities + that might relate to the BlackByte ransomware, including looking for file writes + associated with BlackByte, persistence, initial access, account registry + modification and more. +narrative: BlackByte ransomware campaigns targeting business operations, + involve the use of ransomware payloads, infection chain to collect and exfiltrate data and drop payload on the targeted system. + BlackByte Ransomware operates by infiltrating a system through various methods, such as malicious email attachments, exploit kits, + or compromised websites. Once inside a system, it begins encrypting files using strong encryption algorithms, rendering them unusable. + After completing the encryption process, BlackByte Ransomware typically leaves a ransom note that explains the situation to the victim + and provides instructions on how to pay the ransom to obtain the decryption key. +references: +- https://www.microsoft.com/en-us/security/blog/2023/07/06/the-five-day-job-a-blackbyte-ransomware-intrusion-case-study/ +tags: + analytic_story: BlackByte Ransomware + category: + - Malware + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection