Files
2021-09-27 18:54:15 +00:00

4.7 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Clop Ransomware 2021-03-17 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-03-17
  • Author: Rod Soto, Teoderick Contreras, Splunk
  • ID: 5a6f6849-1a26-4fae-aa05-fa730556eeb6

Narrative

Clop ransomware campaigns targeting healthcare and other vertical sectors, involve the use of ransomware payloads along with exfiltration of data per HHS bulletin. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data.

Detections

Name Technique Type
Clop Common Exec Parameter User Execution, Create or Modify System Process, Data Destruction, Service Execution, Inhibit System Recovery, Data Encrypted for Impact, Indicator Removal on Host, Service Stop, Clear Windows Event Logs TTP
Clop Ransomware Known Service Name Create or Modify System Process TTP
Common Ransomware Extensions Data Destruction Hunting
Common Ransomware Notes Data Destruction Hunting
Create Service In Suspicious File Path Service Execution TTP
Deleting Shadow Copies Inhibit System Recovery, Indicator Removal on Host, Clear Windows Event Logs TTP
High File Deletion Frequency Data Destruction Anomaly
High Process Termination Frequency Data Encrypted for Impact Anomaly
Process Deleting Its Process File Path Indicator Removal on Host TTP
Ransomware Notes bulk creation Data Encrypted for Impact Anomaly
Resize ShadowStorage volume Inhibit System Recovery TTP
Resize Shadowstorage Volume Service Stop TTP
Suspicious Event Log Service Behavior Clear Windows Event Logs TTP
Suspicious wevtutil Usage Clear Windows Event Logs TTP
WevtUtil Usage To Clear Logs Clear Windows Event Logs TTP
Windows Event Log Cleared Clear Windows Event Logs TTP

Reference

source | version: 1