PUA - CleanWipe Execution

 Original Source: [Sigma source]
Title: PUA - CleanWipe Execution
Status: test
Description:Detects the use of CleanWipe a tool usually used to delete Symantec antivirus.
References:
  -https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Other/CleanWipe
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2021-12-18
modified:2023-02-14
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection1:
    Image|endswith: '\SepRemovalToolNative_x64.exe'
  selection2:
    Image|endswith: '\CATClean.exe'
    CommandLine|contains: '--uninstall'
  selection3:
    Image|endswith: '\NetInstaller.exe'
    CommandLine|contains: '-r'
  selection4:
    Image|endswith: '\WFPUnins.exe'
    CommandLine|contains|all:
      -'/uninstall'
      -'/enterprise'

  condition:1 of selection*
Falsepositives:
  -Legitimate administrative use (Should be investigated either way)
Level: high