mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
analyticstory
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
name: Hermetic Wiper
|
||||
id:
|
||||
version: 1
|
||||
date: '2022-03-02'
|
||||
author: Teoderick Contreras, Rod Soto, Michael Haag, Splunk
|
||||
description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities
|
||||
that might relate to the destructive malware targeting Ukrainian organizations also known as "Hermetic Wiper". This analytic
|
||||
story looks for abuse of Regsvr32, Executables written in administrative SMB Share, Suspcious processes, Disabling of Memory Crash DUmp and more.
|
||||
narrative: Hermetic Wiper is destructive malware operation found by Sentinel One targeting
|
||||
multiple organizations in Ukraine. This malicious payload corrupts Master Boot Records, uses signed drivers and manipulates NTFS attributes for file destruction.
|
||||
references:
|
||||
- https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/
|
||||
- https://www.cisa.gov/uscert/ncas/alerts/aa22-057a
|
||||
tags:
|
||||
analytic_story: Hermetic Wiper
|
||||
category:
|
||||
- Malware
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
Reference in New Issue
Block a user