Sigma Rule Library

HAFNIUM Exchange Exploitation Activity

Detects activity observed by different researchers to be HAFNIUM group activity (or related) on Exchange servers

View on GitHubOpen raw file

Detection logic

selection_attrib

CommandLine|contains|all:
  - attrib
  - " +h "
  - " +s "
  - " +r "
  - .aspx

selection_vsperfmon

- Image|contains: \ProgramData\VSPerfMon\
- CommandLine|contains|all:
    - schtasks
    - VSPerfMon

selection_opera_1

Image|endswith: Opera_browser.exe
ParentImage|endswith:
  - \services.exe
  - \svchost.exe

selection_opera_2

Image|endswith: Users\Public\opera\Opera_browser.exe

selection_vssadmin

CommandLine|contains|all:
  - vssadmin list shadows
  - Temp\__output

selection_makecab_1

Image|endswith: \makecab.exe
CommandLine|contains|all:
  - inetpub\wwwroot\
  - .dmp.zip

selection_makecab_2

Image|endswith: \makecab.exe
CommandLine|contains:
  - Microsoft\Exchange Server\
  - compressionmemory
  - .gif

selection_7zip

CommandLine|contains|all:
  - " -t7z "
  - C:\Programdata\pst
  - \it.zip

selection_rundll32

CommandLine|contains|all:
  - \comsvcs.dll
  - Minidump
  - "full "
  - \inetpub\wwwroot

selection_other

CommandLine|contains:
  - Windows\Temp\xx.bat
  - Windows\WwanSvcdcs
  - Windows\Temp\cw.exe

Condition

1 of selection*

Raw YAML

title: HAFNIUM Exchange Exploitation Activity
id: bbb2dedd-a0e3-46ab-ba6c-6c82ae7a9aa7
status: test
description: Detects activity observed by different researchers to be HAFNIUM group activity (or related) on Exchange servers
references:
    - https://blog.truesec.com/2021/03/07/exchange-zero-day-proxylogon-and-hafnium/
    - https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
    - https://discuss.elastic.co/t/detection-and-response-for-hafnium-activity/266289/3
    - https://twitter.com/GadixCRK/status/1369313704869834753?s=20
    - https://twitter.com/BleepinComputer/status/1372218235949617161
author: Florian Roth (Nextron Systems)
date: 2021-03-09
modified: 2023-03-09
tags:
    - attack.privilege-escalation
    - attack.execution
    - attack.persistence
    - attack.t1546
    - attack.t1053
    - attack.g0125
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection_attrib:
        CommandLine|contains|all:
            - 'attrib'
            - ' +h '
            - ' +s '
            - ' +r '
            - '.aspx'
    selection_vsperfmon:
        - Image|contains: '\ProgramData\VSPerfMon\'
        - CommandLine|contains|all:
              - 'schtasks'
              - 'VSPerfMon'
    selection_opera_1:
        Image|endswith: 'Opera_browser.exe'
        ParentImage|endswith:
            - '\services.exe'
            - '\svchost.exe'
    selection_opera_2:
        Image|endswith: 'Users\Public\opera\Opera_browser.exe'
    selection_vssadmin:
        CommandLine|contains|all:
            - 'vssadmin list shadows'
            - 'Temp\__output'
    selection_makecab_1:
        Image|endswith: '\makecab.exe'
        CommandLine|contains|all:
            - 'inetpub\wwwroot\'
            - '.dmp.zip'
    selection_makecab_2:
        Image|endswith: '\makecab.exe'
        CommandLine|contains:
            - 'Microsoft\Exchange Server\'
            - 'compressionmemory'
            - '.gif'
    selection_7zip:
        CommandLine|contains|all:
            - ' -t7z '
            - 'C:\Programdata\pst'
            - '\it.zip'
    selection_rundll32:
        CommandLine|contains|all:
            - '\comsvcs.dll'
            - 'Minidump'
            - 'full '
            - '\inetpub\wwwroot'
    selection_other:
        CommandLine|contains:
            - 'Windows\Temp\xx.bat'
            - 'Windows\WwanSvcdcs'
            - 'Windows\Temp\cw.exe'
    condition: 1 of selection*
falsepositives:
    - Unlikely
level: critical

False positives

  • Unlikely

References

Similar rules