Files
splunk-security_content/docs/_stories/whispergate.md
2022-03-09 11:36:28 +01:00

4.3 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
WhisperGate 2022-01-19 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Actions on Objectives
Command and Control
Exploitation
Installation

Try in Splunk Security Cloud{: .btn .btn--success}

Description

This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the destructive malware targeting Ukrainian organizations also known as "WhisperGate". This analytic story looks for suspicious process execution, command-line activity, downloads, DNS queries and more.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2022-01-19
  • Author: Teoderick Contreras, Splunk
  • ID: 0150e6e5-3171-442e-83f8-1ccd8599569b

Narrative

WhisperGate/DEV-0586 is destructive malware operation found by MSTIC (Microsoft Threat Inteligence Center) targeting multiple organizations in Ukraine. This operation campaign consist of several malware component like the downloader that abuses discord platform, overwrite or destroy master boot record (MBR) of the targeted host, wiper and also windows defender evasion techniques.

Detections

Name Technique Type
Add or Set Windows Defender Exclusion None TTP
Attempt To Stop Security Service None TTP
CMD Carry Out String Command Parameter None Hunting
Excessive File Deletion In WinDefender Folder None TTP
Executables Or Script Creation In Suspicious Path None TTP
Impacket Lateral Movement Commandline Parameters None TTP
Malicious PowerShell Process - Encoded Command None Hunting
Ping Sleep Batch Command None Anomaly
Powershell Remove Windows Defender Directory None TTP
Powershell Windows Defender Exclusion Commands None TTP
Process Deleting Its Process File Path None TTP
Suspicious Process DNS Query Known Abuse Web Services None TTP
Suspicious Process File Path None TTP
Suspicious Process With Discord DNS Query None Anomaly
Windows DotNet Binary in Non Standard Path None TTP
Windows High File Deletion Frequency None Anomaly
Windows InstallUtil in Non Standard Path None TTP
Windows NirSoft AdvancedRun None TTP
Windows NirSoft Utilities None Hunting
Windows Raw Access To Master Boot Record Drive None TTP
Wscript Or Cscript Suspicious Child Process None TTP

Reference

source | version: 1