Files
splunk-security_content/docs/_stories/ransomware.md
2022-03-09 11:36:28 +01:00

9.1 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Ransomware 2020-02-04 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Network_Traffic
Actions on Objectives
Command and Control
Delivery
Exploitation
Reconnaissance

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint, Network_Traffic
  • Last Updated: 2020-02-04
  • Author: David Dorsey, Splunk
  • ID: cf309d0d-d4aa-4fbb-963d-1e79febd3756

Narrative

Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware.

Detections

Name Technique Type
Scheduled tasks used in BadRabbit ransomware None TTP
7zip CommandLine To SMB Share Path None Hunting
Allow File And Printing Sharing In Firewall None TTP
Allow Network Discovery In Firewall None TTP
Allow Operation with Consent Admin None TTP
BCDEdit Failure Recovery Modification None TTP
Clear Unallocated Sector Using Cipher App None TTP
CMLUA Or CMSTPLUA UAC Bypass None TTP
Common Ransomware Extensions None Hunting
Common Ransomware Notes None Hunting
Conti Common Exec parameter None TTP
Delete ShadowCopy With PowerShell None TTP
Deleting Shadow Copies None TTP
Detect RClone Command-Line Usage None TTP
Detect Renamed RClone None Hunting
Detect SharpHound Command-Line Arguments None TTP
Detect SharpHound File Modifications None TTP
Detect SharpHound Usage None TTP
Disable AMSI Through Registry None TTP
Disable ETW Through Registry None TTP
Disable Logs Using WevtUtil None TTP
Disable Windows Behavior Monitoring None TTP
Excessive Service Stop Attempt None Anomaly
Excessive Usage Of Net App None Anomaly
Excessive Usage Of SC Service Utility None Anomaly
Execute Javascript With Jscript COM CLSID None TTP
Fsutil Zeroing File None TTP
ICACLS Grant Command None TTP
Known Services Killed by Ransomware None TTP
Modification Of Wallpaper None TTP
Msmpeng Application DLL Side Loading None TTP
Permission Modification using Takeown App None TTP
Powershell Disable Security Monitoring None TTP
Powershell Enable SMB1Protocol Feature None TTP
Powershell Execute COM Object None TTP
Prevent Automatic Repair Mode using Bcdedit None TTP
Recon AVProduct Through Pwh or WMI None TTP
Recursive Delete of Directory In Batch CMD None TTP
Registry Keys Used For Persistence None TTP
Remote Process Instantiation via WMI None TTP
Revil Common Exec Parameter None TTP
Revil Registry Entry None TTP
Schtasks used for forcing a reboot None TTP
Start Up During Safe Mode Boot None TTP
Suspicious Event Log Service Behavior None TTP
Suspicious Scheduled Task from Public Directory None Anomaly
Suspicious wevtutil Usage None TTP
System Processes Run From Unexpected Locations None TTP
UAC Bypass With Colorui COM Object None TTP
Uninstall App Using MsiExec None TTP
USN Journal Deletion None TTP
WBAdmin Delete System Backups None TTP
Wbemprox COM Object Execution None TTP
Windows Disable Memory Crash Dump None TTP
Windows DiskCryptor Usage None Hunting
Windows DotNet Binary in Non Standard Path None TTP
Windows Event Log Cleared None TTP
Windows InstallUtil in Non Standard Path None TTP
Windows NirSoft AdvancedRun None TTP
Windows Raccine Scheduled Task Deletion None TTP
WinEvent Scheduled Task Created to Spawn Shell None TTP
WinEvent Scheduled Task Created Within Public Path None TTP
Microsoft Exchange Mailbox Replication service writing Active Server Pages None TTP
Spike in File Writes None Anomaly
Unusually Long Command Line None Anomaly
Unusually Long Command Line - MLTK None Anomaly
Prohibited Network Traffic Allowed None TTP
SMB Traffic Spike None Anomaly
SMB Traffic Spike - MLTK None Anomaly
TOR Traffic None TTP

Reference

source | version: 1