Sigma Rule Library

SNAKE Malware Installer Name Indicators

Detects filename indicators associated with the SNAKE malware as reported by CISA in their report

View on GitHubOpen raw file

Detection logic

selection

TargetFilename|endswith:
  - \jpsetup.exe
  - \jpinst.exe

Condition

selection

Raw YAML

title: SNAKE Malware Installer Name Indicators
id: 99eccc2b-7182-442f-8806-b76cc36d866b
status: test
description: Detects filename indicators associated with the SNAKE malware as reported by CISA in their report
references:
    - https://media.defense.gov/2023/May/09/2003218554/-1/-1/0/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-05-10
tags:
    - attack.execution
    - detection.emerging-threats
logsource:
    category: file_event
    product: windows
detection:
    selection:
        TargetFilename|endswith:
            - '\jpsetup.exe'
            - '\jpinst.exe'
    condition: selection
falsepositives:
    - Some legitimate software was also seen using these names. Apply additional filters and use this rule as a hunting basis.
level: low

False positives

  • Some legitimate software was also seen using these names. Apply additional filters and use this rule as a hunting basis.

References

Similar rules