This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Ping/Del Command Combination
Original Source:
[Sigma source]
Title:
Suspicious Ping/Del Command Combination
Status:
test
Description:
Detects a method often used by ransomware. Which combines the "ping" to wait a couple of seconds and then "del" to delete the file in question. Its used to hide the file responsible for the initial infection for example
References:
-https://blog.sygnia.co/kaseya-ransomware-supply-chain-attack
-https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/06/23093553/Common-TTPs-of-the-modern-ransomware_low-res.pdf
-https://www.acronis.com/en-us/blog/posts/lockbit-ransomware/
-https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackbyte-exbyte-ransomware
Author:
Ilya Krestinichev
Date:
2022-11-03
modified:
2024-03-05
Tags:
-'attack.stealth'
-'attack.t1070.004'
Logsource:
category: process_creation
product: windows
Detection:
selection_count:
CommandLine|contains|windash
:
' -n '
selection_nul:
CommandLine|contains
:
'Nul'
selection_del_param:
CommandLine|contains|windash
:
-' -f '
-' -q '
selection_all:
CommandLine|contains|all
:
-'ping'
-'del '
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high