Sigma Rule Library

EvilNum APT Golden Chickens Deployment Via OCX Files

Detects Golden Chickens deployment method as used by Evilnum and described in ESET July 2020 report

View on GitHubOpen raw file

Detection logic

selection

CommandLine|contains|all:
  - regsvr32
  - /s
  - /i
  - \AppData\Roaming\
  - .ocx

Condition

selection

Raw YAML

title: EvilNum APT Golden Chickens Deployment Via OCX Files
id: 8acf3cfa-1e8c-4099-83de-a0c4038e18f0
status: test
description: Detects Golden Chickens deployment method as used by Evilnum and described in ESET July 2020 report
references:
    - https://www.welivesecurity.com/2020/07/09/more-evil-deep-look-evilnum-toolset/
    - https://app.any.run/tasks/33d37fdf-158d-4930-aa68-813e1d5eb8ba/
author: Florian Roth (Nextron Systems)
date: 2020-07-10
modified: 2023-03-09
tags:
    - attack.stealth
    - attack.t1218.011
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains|all:
            - 'regsvr32'
            - '/s'
            - '/i'
            - '\AppData\Roaming\'
            - '.ocx'
    condition: selection
falsepositives:
    - Unknown
level: critical

False positives

  • Unknown

References

Similar rules