mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3.6 KiB
3.6 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | |||||
|---|---|---|---|---|---|---|---|---|---|
| Hermetic Wiper | 2022-03-02 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the destructive malware targeting Ukrainian organizations also known as "Hermetic Wiper". This analytic story looks for abuse of Regsvr32, executables written in administrative SMB Share, suspicious processes, disabling of memory crash dump and more.
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2022-03-02
- Author: Teoderick Contreras, Rod Soto, Michael Haag, Splunk
- ID: b7511c2e-9a10-11ec-99e3-acde48001122
Narrative
Hermetic Wiper is destructive malware operation found by Sentinel One targeting multiple organizations in Ukraine. This malicious payload corrupts Master Boot Records, uses signed drivers and manipulates NTFS attributes for file destruction.
Detections
Reference
- https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/
- https://www.cisa.gov/uscert/ncas/alerts/aa22-057a
source | version: 1