REvil Kaseya Incident Malware Patterns
Detects process command line patterns and locations used by REvil group in Kaseya incident (can also match on other malware)
Sigma rule (View on GitHub)
1title: REvil Kaseya Incident Malware Patterns
2id: 5de632bc-7fbd-4c8a-944a-fce55c59eae5
3status: test
4description: Detects process command line patterns and locations used by REvil group in Kaseya incident (can also match on other malware)
5references:
6 - https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers
7 - https://www.joesandbox.com/analysis/443736/0/html
8 - https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b
9 - https://therecord.media/revil-ransomware-executes-supply-chain-attack-via-malicious-kaseya-update/
10 - https://blog.truesec.com/2021/07/04/kaseya-supply-chain-attack-targeting-msps-to-deliver-revil-ransomware/
11author: Florian Roth (Nextron Systems)
12date: 2021-07-03
13modified: 2022-05-20
14tags:
15 - attack.execution
16 - attack.t1059
17 - attack.g0115
18 - detection.emerging-threats
19logsource:
20 category: process_creation
21 product: windows
22detection:
23 selection1:
24 CommandLine|contains:
25 - 'C:\Windows\cert.exe'
26 - 'del /q /f c:\kworking\agent.crt'
27 - 'Kaseya VSA Agent Hot-fix'
28 - '\AppData\Local\Temp\MsMpEng.exe'
29 - 'rmdir /s /q %SystemDrive%\inetpub\logs'
30 - 'del /s /q /f %SystemDrive%\\*.log'
31 - 'c:\kworking1\agent.exe'
32 - 'c:\kworking1\agent.crt'
33 selection2:
34 Image:
35 - 'C:\Windows\MsMpEng.exe'
36 - 'C:\Windows\cert.exe'
37 - 'C:\kworking\agent.exe'
38 - 'C:\kworking1\agent.exe'
39 selection3:
40 CommandLine|contains|all:
41 - 'del /s /q /f'
42 - 'WebPages\Errors\webErrorLog.txt'
43 condition: 1 of selection*
44falsepositives:
45 - Unknown
46level: critical
References
Related rules
- Lazarus Group Activity
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
- Potential CVE-2021-40444 Exploitation Attempt
- Potential KamiKakaBot Activity - Lure Document Execution
- Turla Group Lateral Movement