4.3 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | ||||
|---|---|---|---|---|---|---|---|---|
| WhisperGate | 2022-01-19 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the destructive malware targeting Ukrainian organizations also known as "WhisperGate". This analytic story looks for suspicious process execution, command-line activity, downloads, DNS queries and more.
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2022-01-19
- Author: Teoderick Contreras, Splunk
- ID: 0150e6e5-3171-442e-83f8-1ccd8599569b
Narrative
WhisperGate/DEV-0586 is destructive malware operation found by MSTIC (Microsoft Threat Inteligence Center) targeting multiple organizations in Ukraine. This operation campaign consist of several malware component like the downloader that abuses discord platform, overwrite or destroy master boot record (MBR) of the targeted host, wiper and also windows defender evasion techniques.
Detections
Reference
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
- https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3
source | version: 1