Files
splunk-security_content/detections/endpoint/clop_common_exec_parameter.yml

54 lines
2.5 KiB
YAML

name: Clop Common Exec Parameter
id: 5a8a2a72-8322-11eb-9ee9-acde48001122
version: 1
date: '2021-03-17'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: The following analytics are designed to identifies some CLOP ransomware
variant that using arguments to execute its main code or feature of its code. In
this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files
in network shares and if it is "temp.dat", it will try to read from some stream
pipe or file start encrypting files within the infected local machines. This technique
can be also identified as an anti-sandbox technique to make its code non-responsive
since it is waiting for some parameter to execute properly.
search: '| tstats `security_content_summariesonly` values(Processes.process) as cmdline
values(Processes.parent_process_name) as parent_process values(Processes.process_name)
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name != "*temp.dat*" Processes.process = "*runrun*" OR Processes.process
= "*temp.dat*" by Processes.parent_process_name Processes.process_name Processes.process
Processes.dest Processes.user Processes.process_id Processes.process_guid | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clop_common_exec_parameter_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: Operators can execute third party tools using these parameters.
references:
- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html
- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html
tags:
analytic_story:
- Clop Ransomware
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log
kill_chain_phases:
- Obfuscation
mitre_attack_id:
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- Processes.process
- Processes.parent_process_name
- _time
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process_id
security_domain: endpoint