mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
18 lines
1.3 KiB
YAML
18 lines
1.3 KiB
YAML
name: Winter Vivern
|
|
id: 5ce5f311-b311-4568-90ca-0c36781d07a4
|
|
version: 1
|
|
date: '2023-02-16'
|
|
author: Teoderick Contreras, Splunk
|
|
description: Utilize searches that enable you to detect and investigate unusual activities potentially related to the Winter Vivern malicious software. This includes examining multiple timeout executions, scheduled task creations, screenshots, and downloading files through PowerShell, among other indicators.
|
|
narrative: The Winter Vivern malware, identified by CERT UA, is designed to download and run multiple PowerShell scripts on targeted hosts. These scripts aim to gather a variety of files with specific extensions, including (.edb, .ems, .eme, .emz, .key, .pem, .ovpn, .bat, .cer, .p12, .cfg, .log, .txt, .pdf, .doc, .docx, .xls, .xlsx, and .rdg), primarily from desktop directories. In addition to this, the malware captures desktop screenshots and performs data exfiltration using HTTP. To maintain its presence on the targeted host, Winter Vivern also establishes a persistence mechanism, such as creating a scheduled task.
|
|
references:
|
|
- https://cert.gov.ua/article/3761023
|
|
tags:
|
|
analytic_story: Winter Vivern
|
|
category:
|
|
- Malware
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection |