Sigma Rule Library

Hermetic Wiper TG Process Patterns

Detects process execution patterns found in intrusions related to the Hermetic Wiper malware attacks against Ukraine in February 2022

View on GitHubOpen raw file

Detection logic

selection1

Image|endswith: \policydefinitions\postgresql.exe

selection2

- CommandLine|contains:
    - CSIDL_SYSTEM_DRIVE\temp\sys.tmp
    - " 1> \\\\\\\\127.0.0.1\\ADMIN$\\__16"
- CommandLine|contains|all:
    - "powershell -c "
    - "\\comsvcs.dll MiniDump "
    - \winupd.log full

Condition

1 of selection*

Raw YAML

title: Hermetic Wiper TG Process Patterns
id: 2f974656-6d83-4059-bbdf-68ac5403422f
status: test
description: Detects process execution patterns found in intrusions related to the Hermetic Wiper malware attacks against Ukraine in February 2022
references:
    - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia
author: Florian Roth (Nextron Systems)
date: 2022-02-25
modified: 2022-09-09
tags:
    - attack.execution
    - attack.lateral-movement
    - attack.t1021.001
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection1:
        Image|endswith: '\policydefinitions\postgresql.exe'
    selection2:
        - CommandLine|contains:
              - 'CSIDL_SYSTEM_DRIVE\temp\sys.tmp'
              - ' 1> \\\\127.0.0.1\ADMIN$\__16'
        - CommandLine|contains|all:
              - 'powershell -c '
              - '\comsvcs.dll MiniDump '
              - '\winupd.log full'
    condition: 1 of selection*
falsepositives:
    - Unknown
level: high

False positives

  • Unknown

References

Similar rules