From d5724fb583e8bc836378f07fceba392f1bb4e7be Mon Sep 17 00:00:00 2001 From: Wagga <6437862+wagga40@users.noreply.github.com> Date: Mon, 29 Aug 2022 07:56:59 +0200 Subject: [PATCH] Update proc_creation_win_susp_advancedrun.yml --- .../process_creation/proc_creation_win_susp_advancedrun.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml b/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml index 79ce72384..24bbed6fd 100644 --- a/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml +++ b/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml @@ -1,7 +1,7 @@ title: Suspicious AdvancedRun Execution id: d2b749ee-4225-417e-b20e-a8d2193cbb84 status: experimental -description: Detects the execution of AdvancedRun utitlity +description: Detects the execution of AdvancedRun utility references: - https://twitter.com/splinter_code/status/1483815103279603714 - https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3