Files
splunk-security_content/docs/_stories/remcos.md
2022-03-09 11:36:28 +01:00

4.9 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Remcos 2021-09-23 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Actions on Objectives
Exploitation
Reconnaissance

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the Remcos RAT trojan, including looking for file writes associated with its payload, screencapture, registry modification, UAC bypassed, persistence and data collection..

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-09-23
  • Author: Teoderick Contreras, Splunk
  • ID: 2bd4aa08-b9a5-40cf-bfe5-7d43f13d496c

Narrative

Remcos or Remote Control and Surveillance, marketed as a legitimate software for remotely managing Windows systems is now widely used in multiple malicious campaigns both APT and commodity malware by threat actors.

Detections

Name Technique Type
Add or Set Windows Defender Exclusion None TTP
Disabling Remote User Account Control None TTP
Executables Or Script Creation In Suspicious Path None TTP
Jscript Execution Using Cscript App None TTP
Loading Of Dynwrapx Module None TTP
Malicious InProcServer32 Modification None TTP
Non Chrome Process Accessing Chrome Default Dir None Anomaly
Non Firefox Process Access Firefox Profile Dir None Anomaly
Possible Browser Pass View Parameter None Hunting
Powershell Windows Defender Exclusion Commands None TTP
Process Deleting Its Process File Path None TTP
Process Writing DynamicWrapperX None Hunting
Registry Keys Used For Persistence None TTP
Regsvr32 Silent and Install Param Dll Loading None Anomaly
Regsvr32 with Known Silent Switch Cmdline None Anomaly
Remcos client registry install entry None TTP
Remcos RAT File Creation in Remcos Folder None TTP
Suspicious Image Creation In Appdata Folder None TTP
Suspicious Process DNS Query Known Abuse Web Services None TTP
Suspicious Process File Path None TTP
Suspicious WAV file in Appdata Folder None TTP
System Info Gathering Using Dxdiag Application None Hunting
Vbscript Execution Using Wscript App None TTP
Windows Defender Exclusion Registry Entry None TTP
Winhlp32 Spawning a Process None TTP
Wscript Or Cscript Suspicious Child Process None TTP

Reference

source | version: 1