REvil Kaseya Incident Malware Patterns
Detects process command line patterns and locations used by REvil group in Kaseya incident (can also match on other malware)
Detection logic
selection1
CommandLine|contains:
- C:\Windows\cert.exe
- del /q /f c:\kworking\agent.crt
- Kaseya VSA Agent Hot-fix
- \AppData\Local\Temp\MsMpEng.exe
- rmdir /s /q %SystemDrive%\inetpub\logs
- del /s /q /f %SystemDrive%\\*.log
- c:\kworking1\agent.exe
- c:\kworking1\agent.crtselection2
Image:
- C:\Windows\MsMpEng.exe
- C:\Windows\cert.exe
- C:\kworking\agent.exe
- C:\kworking1\agent.exeselection3
CommandLine|contains|all:
- del /s /q /f
- WebPages\Errors\webErrorLog.txtCondition
1 of selection*Raw YAML
title: REvil Kaseya Incident Malware Patterns
id: 5de632bc-7fbd-4c8a-944a-fce55c59eae5
status: test
description: Detects process command line patterns and locations used by REvil group in Kaseya incident (can also match on other malware)
references:
- https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers
- https://www.joesandbox.com/analysis/443736/0/html
- https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b
- https://therecord.media/revil-ransomware-executes-supply-chain-attack-via-malicious-kaseya-update/
- https://blog.truesec.com/2021/07/04/kaseya-supply-chain-attack-targeting-msps-to-deliver-revil-ransomware/
author: Florian Roth (Nextron Systems)
date: 2021-07-03
modified: 2022-05-20
tags:
- attack.execution
- attack.t1059
- attack.g0115
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection1:
CommandLine|contains:
- 'C:\Windows\cert.exe'
- 'del /q /f c:\kworking\agent.crt'
- 'Kaseya VSA Agent Hot-fix'
- '\AppData\Local\Temp\MsMpEng.exe'
- 'rmdir /s /q %SystemDrive%\inetpub\logs'
- 'del /s /q /f %SystemDrive%\\*.log'
- 'c:\kworking1\agent.exe'
- 'c:\kworking1\agent.crt'
selection2:
Image:
- 'C:\Windows\MsMpEng.exe'
- 'C:\Windows\cert.exe'
- 'C:\kworking\agent.exe'
- 'C:\kworking1\agent.exe'
selection3:
CommandLine|contains|all:
- 'del /s /q /f'
- 'WebPages\Errors\webErrorLog.txt'
condition: 1 of selection*
falsepositives:
- Unknown
level: criticalFalse positives
- Unknown
References
- https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers
- https://www.joesandbox.com/analysis/443736/0/html
- https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b
- https://therecord.media/revil-ransomware-executes-supply-chain-attack-via-malicious-kaseya-update/
- https://blog.truesec.com/2021/07/04/kaseya-supply-chain-attack-targeting-msps-to-deliver-revil-ransomware/
Similar rules
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
mediumwindows · Shares T1059
DarkGate - Autoit3.EXE Execution Parameters
highwindows · Shares T1059
Lazarus Group Activity
criticalwindows · Shares T1059
Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
highwindows · Shares T1059