HackTool - Inveigh Execution

 Original Source: [Sigma source]
Title: HackTool - Inveigh Execution
Status: test
Description:Detects the use of Inveigh a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool
References:
  -https://github.com/Kevin-Robertson/Inveigh
  -https://thedfirreport.com/2020/11/23/pysa-mespinoza-ransomware/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-24
modified:2023-02-04
Tags:
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\Inveigh.exe'     - OriginalFileName:
      - '\Inveigh.exe'
      - '\Inveigh.dll'
Description:'Inveigh'     - CommandLine|contains:
      - ' -SpooferIP'
      - ' -ReplyToIPs '
      - ' -ReplyToDomains '
      - ' -ReplyToMACs '
      - ' -SnifferIP'
  condition:selection
Falsepositives:
  -Very unlikely
Level: critical