CodePage Modification Via MODE.COM To Russian Language

 Original Source: [Sigma source]
Title: CodePage Modification Via MODE.COM To Russian Language
Status: test
Description:Detects a CodePage modification using the "mode.com" utility to Russian language. This behavior has been used by threat actors behind Dharma ransomware.
References:
  -https://learn.microsoft.com/en-us/windows/win32/intl/code-page-identifiers
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/mode
  -https://strontic.github.io/xcyclopedia/library/mode.com-59D1ED51ACB8C3D50F1306FD75F20E99.html
  -https://www.virustotal.com/gui/file/5e75ef02517afd6e8ba6462b19217dc4a5a574abb33d10eb0f2bab49d8d48c22/behavior
Author: Joseliyo Sanchez, @Joseliyo_Jstnk
Date: 2024-01-17
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\mode.com' OriginalFileName:'MODE.COM'   selection_cli:
    CommandLine|contains|all:
      -' con '
      -' cp '
      -' select='

    CommandLine|endswith:
      -'=1251'
      -'=866'

  condition:all of selection_*
Falsepositives:
  -Russian speaking people changing the CodePage
Level: medium