Pnscan Binary Data Transmission Activity

 Original Source: [Sigma source]
Title: Pnscan Binary Data Transmission Activity
Status: test
Description:Detects command line patterns associated with the use of Pnscan for sending and receiving binary data across the network. This behavior has been identified in a Linux malware campaign targeting Docker, Apache Hadoop, Redis, and Confluence and was previously used by the threat actor known as TeamTNT
References:
  -https://www.cadosecurity.com/blog/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence
  -https://intezer.com/wp-content/uploads/2021/09/TeamTNT-Cryptomining-Explosion.pdf
  -https://regex101.com/r/RugQYK/1
  -https://www.virustotal.com/gui/file/beddf70a7bab805f0c0b69ac0989db6755949f9f68525c08cb874988353f78a9/content
Author: David Burkett (@signalblur)
Date: 2024-04-16
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1046'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection:
    CommandLine|re: '-(W|R)\s?(\s|"|')([0-9a-fA-F]{2}\s?){2,20}(\s|"|')'
  condition:selection
Falsepositives:
  -Unknown
Level: medium