mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
26 lines
1.3 KiB
YAML
26 lines
1.3 KiB
YAML
name: WhisperGate
|
|
id: 0150e6e5-3171-442e-83f8-1ccd8599569b
|
|
version: 1
|
|
date: '2022-01-19'
|
|
author: Teoderick Contreras, Splunk
|
|
description: This analytic story contains detections that allow security analysts to detect and investigate unusual activities
|
|
that might relate to the destructive malware targeting Ukrainian organizations also known as "WhisperGate". This analytic
|
|
story looks for suspicious process execution, command-line activity, downloads, DNS queries and more.
|
|
narrative: WhisperGate/DEV-0586 is destructive malware operation found by MSTIC (Microsoft Threat Inteligence Center) targeting
|
|
multiple organizations in Ukraine. This operation campaign consist of several malware component like the downloader that abuses discord platform,
|
|
overwrite or destroy master boot record (MBR) of the targeted host, wiper and also windows defender evasion techniques.
|
|
references:
|
|
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
|
- https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3
|
|
tags:
|
|
analytic_story: WhisperGate
|
|
category:
|
|
- Data Destruction
|
|
- Malware
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|