gelup_malware_detector_sysmon_behavior
Description
This content detects charactaristics that are attributed to the Gelup Malware Strain License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
Query · yara_l
events:
(($selection1.metadata.product_event_type = "11" and ($selection1.target.file.full_path = "C:\\Windows \\System32\\propsys.dll" or $selection1.target.file.full_path = "C:\\Windows \\System32\\ComputerDefaults.exe" or re.regex($selection1.target.file.full_path, `C:\\Users.*\\AppData\\Roaming\\MSOCache.*\.xml`) or re.regex($selection1.target.file.full_path, `C:\\Users.*\\AppData\\Local\\Temp\\tmpaddon_bak`) or re.regex($selection1.target.file.full_path, `.*schetasks\.exe`) or $selection1.target.file.full_path = "C:\\Windows\\api.config")) or ($selection1.metadata.product_event_type = "1" and re.regex($selection1.target.process.file.full_path, `.*schetasks\.exe`) and re.regex($selection1.target.process.command_line, `schetasks\.exe /create /rl highest /tn .* /sc logon /tr C:\\$Recycle\.Bin.*.*\.lnk`)))
condition:
$selection1