Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity
Detects file indicators of potential exploitation of MOVEit CVE-2023-34362.
Detection logic
selection_generic
TargetFilename|contains:
- \MOVEit Transfer\wwwroot\
- \MOVEitTransfer\wwwroot\
TargetFilename|endswith:
- .7z
- .bat
- .dll
- .exe
- .ps1
- .rar
- .vbe
- .vbs
- .zipselection_known_ioc
TargetFilename|endswith:
- \MOVEit Transfer\wwwroot\_human2.aspx.lnk
- \MOVEit Transfer\wwwroot\_human2.aspx
- \MOVEit Transfer\wwwroot\human2.aspx.lnk
- \MOVEit Transfer\wwwroot\human2.aspx
- \MOVEitTransfer\wwwroot\_human2.aspx.lnk
- \MOVEitTransfer\wwwroot\_human2.aspx
- \MOVEitTransfer\wwwroot\human2.aspx.lnk
- \MOVEitTransfer\wwwroot\human2.aspxselection_compiled_asp
CreationUtcTime|startswith:
- "2023-03- "
- "2023-04- "
- "2023-05- "
- "2023-06- "
TargetFilename|contains|all:
- \Windows\Microsoft.net\Framework64\v
- \Temporary ASP.NET Files\
- App_Web_
TargetFilename|endswith: .dllCondition
1 of selection_*Raw YAML
title: Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity
id: c3b2a774-3152-4989-83c1-7afc48fd1599
status: test
description: Detects file indicators of potential exploitation of MOVEit CVE-2023-34362.
references:
- https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/
- https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
- https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/
- https://www.reddit.com/r/sysadmin/comments/13wxuej/comment/jmhdg55/
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
date: 2023-06-01
modified: 2024-08-13
tags:
- attack.initial-access
- attack.t1190
- cve.2023-34362
- detection.emerging-threats
logsource:
category: file_event
product: windows
detection:
selection_generic:
TargetFilename|contains:
- '\MOVEit Transfer\wwwroot\'
- '\MOVEitTransfer\wwwroot\'
TargetFilename|endswith:
- '.7z'
- '.bat'
- '.dll'
- '.exe'
- '.ps1'
- '.rar'
- '.vbe'
- '.vbs'
- '.zip'
selection_known_ioc:
TargetFilename|endswith:
- '\MOVEit Transfer\wwwroot\_human2.aspx.lnk'
- '\MOVEit Transfer\wwwroot\_human2.aspx'
- '\MOVEit Transfer\wwwroot\human2.aspx.lnk'
- '\MOVEit Transfer\wwwroot\human2.aspx'
- '\MOVEitTransfer\wwwroot\_human2.aspx.lnk'
- '\MOVEitTransfer\wwwroot\_human2.aspx'
- '\MOVEitTransfer\wwwroot\human2.aspx.lnk'
- '\MOVEitTransfer\wwwroot\human2.aspx'
# Uncomment selection if you wanna threat hunt for additional artifacts
# selection_cmdline:
# TargetFilename|contains: ':\Windows\TEMP\'
# TargetFilename|endswith: '.cmdline'
selection_compiled_asp:
CreationUtcTime|startswith:
- '2023-03- '
- '2023-04- '
- '2023-05- '
- '2023-06- '
TargetFilename|contains|all:
- '\Windows\Microsoft.net\Framework64\v'
- '\Temporary ASP.NET Files\'
- 'App_Web_'
TargetFilename|endswith: '.dll'
condition: 1 of selection_*
falsepositives:
- To avoid FP, this rule should only be applied on MOVEit servers.
level: highFalse positives
- To avoid FP, this rule should only be applied on MOVEit servers.
References
- https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/
- https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
- https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/
- https://www.reddit.com/r/sysadmin/comments/13wxuej/comment/jmhdg55/
Similar rules
Potential SAP NetWeaver Webshell Creation
mediumwindows · Shares T1190
Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
criticalwindows · Shares T1190
Potential SAP NetWeaver Webshell Creation - Linux
mediumlinux · Shares T1190
Suspicious File Drop by Exchange
mediumwindows · Shares T1190