mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
25 lines
1.1 KiB
YAML
25 lines
1.1 KiB
YAML
name: Remcos
|
|
id: 2bd4aa08-b9a5-40cf-bfe5-7d43f13d496c
|
|
version: 1
|
|
date: '2021-09-23'
|
|
author: Teoderick Contreras, Splunk
|
|
description: Leverage searches that allow you to detect and investigate unusual activities
|
|
that might relate to the Remcos RAT trojan, including looking for file writes associated
|
|
with its payload, screencapture, registry modification, UAC bypassed, persistence
|
|
and data collection..
|
|
narrative: Remcos or Remote Control and Surveillance, marketed as a legitimate software
|
|
for remotely managing Windows systems is now widely used in multiple malicious campaigns
|
|
both APT and commodity malware by threat actors.
|
|
references:
|
|
- https://success.trendmicro.com/solution/1123281-remcos-malware-information
|
|
- https://attack.mitre.org/software/S0332/
|
|
- https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos#:~:text=Remcos%20(acronym%20of%20Remote%20Control,used%20to%20remotely%20control%20computers.&text=Remcos%20can%20be%20used%20for,been%20used%20in%20hacking%20campaigns.
|
|
tags:
|
|
category:
|
|
- Malware
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|