Suspicious File Created In PerfLogs

 Original Source: [Sigma source]
Title: Suspicious File Created In PerfLogs
Status: test
Description:Detects suspicious file based on their extension being created in "C:\PerfLogs\". Note that this directory mostly contains ".etl" files
References:
  -Internal Research
  -https://labs.withsecure.com/publications/fin7-target-veeam-servers
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-05
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • category: file_event
  • product: windows
Detection:
  selection:
    TargetFilename|startswith: 'C:\PerfLogs\'
    TargetFilename|endswith:
      -'.7z'
      -'.bat'
      -'.bin'
      -'.chm'
      -'.dll'
      -'.exe'
      -'.hta'
      -'.lnk'
      -'.ps1'
      -'.psm1'
      -'.py'
      -'.scr'
      -'.sys'
      -'.vbe'
      -'.vbs'
      -'.zip'

  condition:selection
Falsepositives:
  -Unlikely
Level: medium