Files
blue-team-tools/rules/windows/network_connection/net_connection_win_eqnedt.yml
T
Nasreddine Bencherchali 7c38a5c496 chore: add nextron authors tag
2023-02-01 11:14:59 +01:00

23 lines
673 B
YAML
Executable File

title: Equation Editor Network Connection
id: a66bc059-c370-472c-a0d7-f8fd1bf9d583
status: experimental
description: Detects network connections from Equation Editor
references:
- https://twitter.com/forensicitguy/status/1513538712986079238
- https://news.sophos.com/en-us/2019/07/18/a-new-equation-editor-exploit-goes-commercial-as-maldoc-attacks-using-it-spike/
author: Max Altgelt (Nextron Systems)
date: 2022/04/14
tags:
- attack.execution
- attack.t1203
logsource:
category: network_connection
product: windows
detection:
selection:
Image|endswith: '\eqnedt32.exe'
condition: selection
falsepositives:
- Unknown
level: high