Title:
Access To Crypto Currency Wallets By Uncommon Applications
Status:
test
Description:Detects file access requests to crypto currency files by uncommon processes.
Could indicate potential attempt of crypto currency wallet stealing.
References:
-Internal Research
Author: X__Junior (Nextron Systems)
Date: 2024-07-29
modified:None
Tags:
- -'attack.t1003'
- -'attack.credential-access'
Logsource:
- category: file_access
- product: windows
- definition: Requirements: Microsoft-Windows-Kernel-File ETW provider
Detection:
selection:
- FileName|contains:
- '\AppData\Roaming\Ethereum\keystore\'
- '\AppData\Roaming\EthereumClassic\keystore\'
- '\AppData\Roaming\monero\wallets\'
- FileName|endswith:
- '\AppData\Roaming\Bitcoin\wallet.dat'
- '\AppData\Roaming\BitcoinABC\wallet.dat'
- '\AppData\Roaming\BitcoinSV\wallet.dat'
- '\AppData\Roaming\DashCore\wallet.dat'
- '\AppData\Roaming\DogeCoin\wallet.dat'
- '\AppData\Roaming\Litecoin\wallet.dat'
- '\AppData\Roaming\Ripple\wallet.dat'
- '\AppData\Roaming\Zcash\wallet.dat'
filter_main_system:
Image:
'System'
filter_main_generic:
Image|startswith:
-'C:\Program Files (x86)\'
-'C:\Program Files\'
-'C:\Windows\system32\'
-'C:\Windows\SysWOW64\'
filter_optional_defender:
Image|startswith:
'C:\ProgramData\Microsoft\Windows Defender\'
Image|endswith:
-'\MpCopyAccelerator.exe'
-'\MsMpEng.exe'
condition:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Antivirus, Anti-Spyware, Anti-Malware Software
-Backup software
-Legitimate software installed on partitions other than "C:\"
-Searching software such as "everything.exe"
Level:
medium