Skip to content

Commit d5dc059

Browse files
authored
Suspicious ZoneIdentifier detected
1 parent 64bc21e commit d5dc059

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

s1_powerquery_hunting.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -409,5 +409,10 @@
409409
"category" : "Malware & Threats",
410410
"name" : ".NET ClickOnce installation",
411411
"query" : "src.process.name = \"rundll32.exe\" #cmdline contains:anycase \"ShOpenVerbApplication\" #cmdline contains:anycase (\"http\",\".application\")\n| group _FirstSeenMs=min(event.time), _LastSeenMs=max(event.time), Count=count() by endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.process.cmdline, event.dns.request\n| let _firstSeenNs = _FirstSeenMs * 1000000\n| let _lastSeenNs = _LastSeenMs * 1000000\n| columns \"first.timestamp\" = _firstSeenNs, \"last.timestamp\" = _lastSeenNs, endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.process.cmdline, event.dns.request, Count\n| sort -Count\n| limit 100000\n"
412+
},
413+
{
414+
"category" : "Malware & Threats",
415+
"name" : "Suspicious ZoneIdentifier detected",
416+
"query" : "indicator.name contains:anycase \"WriteToADS\" AND indicator.metadata contains:anycase \"Zone.Identifier\" AND ((indicator.metadata contains:anycase 'C:\\\\Perflogs\\\\' OR indicator.metadata contains:anycase '\\\\$Recycle.bin\\\\' OR indicator.metadata contains:anycase '\\\\config\\\\systemprofile\\\\' OR indicator.metadata contains:anycase '\\\\Intel\\\\Logs\\\\' OR indicator.metadata contains:anycase '\\\\RSA\\\\MachineKeys\\\\' OR indicator.metadata contains:anycase '\\\\Users\\\\All Users\\\\' OR indicator.metadata contains:anycase '\\\\Users\\\\Default\\\\' OR indicator.metadata contains:anycase '\\\\Users\\\\NetworkService\\\\' OR indicator.metadata contains:anycase '\\\\Users\\\\Public\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\addins\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\debug\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\Fonts\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\Help\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\IME\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\Media\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\repair\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\security\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\System32\\\\Tasks\\\\' OR indicator.metadata contains:anycase '\\\\Windows\\\\Tasks\\\\') AND NOT (indicator.metadata contains:anycase 'firefox' OR indicator.metadata contains:anycase 'citrix' OR indicator.metadata contains:anycase 'splunkd.exe' OR indicator.metadata contains:anycase 'ldapadmin.exe' OR indicator.metadata contains:anycase 'acslaunch_win' OR indicator.metadata contains:anycase 'gotoassist' OR src.process.user contains:anycase (\"system\",\"syst\u00e8me\")))\n| group _FirstSeenMs=min(event.time), _LastSeenMs=max(event.time), Count=count() by indicator.name, indicator.description, indicator.metadata \n| let _firstSeenNs = _FirstSeenMs * 1000000\n| let _lastSeenNs = _LastSeenMs * 1000000\n| columns \"first.timestamp\" = _firstSeenNs, \"last.timestamp\" = _lastSeenNs, indicator.name, indicator.description, indicator.metadata, Count\n| sort -Count\n| limit 100000"
412417
}
413418
]

0 commit comments

Comments
 (0)