Suspicious Ping/Del Command Combination

 Original Source: [Sigma source]
Title: Suspicious Ping/Del Command Combination
Status: test
Description:Detects a method often used by ransomware. Which combines the "ping" to wait a couple of seconds and then "del" to delete the file in question. Its used to hide the file responsible for the initial infection for example
References:
  -https://blog.sygnia.co/kaseya-ransomware-supply-chain-attack
  -https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/06/23093553/Common-TTPs-of-the-modern-ransomware_low-res.pdf
  -https://www.acronis.com/en-us/blog/posts/lockbit-ransomware/
  -https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackbyte-exbyte-ransomware
Author: Ilya Krestinichev
Date: 2022-11-03
modified:2024-03-05
Tags:
  • -'attack.stealth'
  • -'attack.t1070.004'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_count:
    CommandLine|contains|windash: ' -n '
  selection_nul:
    CommandLine|contains: 'Nul'
  selection_del_param:
    CommandLine|contains|windash:
      -' -f '
      -' -q '

  selection_all:
    CommandLine|contains|all:
      -'ping'
      -'del '

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high