Files
splunk-security_content/detections/endpoint/process_deleting_its_process_file_path.yml

75 lines
2.6 KiB
YAML

name: Process Deleting Its Process File Path
id: f7eda4bc-871c-11eb-b110-acde48001122
version: 2
date: '2022-02-18'
author: Teoderick Contreras
type: TTP
datamodel:
- Endpoint
description: This detection is to identify a suspicious process that tries to delete
the process file path related to its process. This technique is known to be defense
evasion once a certain condition of malware is satisfied or not. Clop ransomware
use this technique where it will try to delete its process file path using a .bat
command if the keyboard layout is not the layout it tries to infect.
search: '`sysmon` EventCode=1 CommandLine = "* /c *" CommandLine = "* del*" Image
= "*\\cmd.exe" | eval result = if(like(process,"%".parent_process."%"), "Found",
"Not Found") | stats min(_time) as firstTime max(_time) as lastTime count by Computer
user ParentImage ParentCommandLine Image CommandLine EventCode ProcessID result
| where result = "Found" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `process_deleting_its_process_file_path_filter`'
how_to_implement: You must be ingesting data that records process activity from your
hosts to populate the Endpoint data model in the Processes node. You must also be
ingesting logs with both the process name and command line from your endpoints.
The command-line arguments are mapped to the "process" field in the Endpoint data
model.
known_false_positives: unknown
references:
- https://www.mandiant.com/resources/fin11-email-campaigns-precursor-for-ransomware-data-theft
- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
tags:
analytic_story:
- Clop Ransomware
- Remcos
- WhisperGate
confidence: 100
context:
- Source:Endpoint
- Stage:Credential Access
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log
impact: 60
kill_chain_phases:
- Exploitation
message: A process $Image$ tries to delete its process path in commandline $cmdline$
as part of defense evasion in host $Computer$
mitre_attack_id:
- T1070
observable:
- name: Computer
type: Hostname
role:
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- EventCode
- Computer
- user
- ParentImage
- ParentCommandLine
- Image
- cmdline
- ProcessID
- result
- _time
risk_score: 60
security_domain: endpoint
asset_type: Endpoint