Files
blue-team-tools/rules/windows/process_creation/proc_creation_win_renamed_megasync.yml
T
Nasreddine Bencherchali 1f34cecadf fix: multiple typos
Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
2023-02-06 12:28:45 +01:00

26 lines
774 B
YAML

title: Renamed MegaSync Execution
id: 643bdcac-8b82-49f4-9fd9-25a90b929f3b
status: test
description: Detects the execution of a renamed MegaSync.exe as seen used by ransomware families like Nefilim, Sodinokibi, Pysa, and Conti.
references:
- https://redcanary.com/blog/rclone-mega-extortion/
author: Sittikorn S
date: 2021/06/22
modified: 2023/02/03
tags:
- attack.defense_evasion
- attack.t1218
logsource:
product: windows
category: process_creation
detection:
selection:
OriginalFileName: 'megasync.exe'
filter:
Image|endswith: '\megasync.exe'
condition: selection and not filter
falsepositives:
- Software that illegally integrates MegaSync in a renamed form
- Administrators that have renamed MegaSync
level: high