[rule]
description = """
Identifies INETCookies file deletion by unsigned process, consistent with the Remcos Remote Access Trojan (RAT)
behavior. Remcos RAT is used by attackers to perform actions on infected machines remotely.
"""
id = "cf7592cc-6954-4973-92ee-213c5eea0fa5"
license = "Elastic License v2"
name = "Remcos RAT INETCookies File Deletion"
os_list = ["windows"]
reference = [
"https://any.run/malware-trends/remcos",
"https://attack.mitre.org/software/S0332/",
"https://www.elastic.co/security-labs/dissecting-remcos-rat-part-four",
]
version = "1.0.4"
query = '''
file where event.action == "deletion" and file.name : "container.dat" and user.id != "S-1-5-18" and
(process.code_signature.trusted == false or process.code_signature.exists == false) and
file.path : "?:\\Users\\*\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\container.dat" and
not process.executable : "C:\\Program Files (x86)\\WinDirStat\\windirstat.exe"
'''
min_endpoint_version = "8.1.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0
[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0
[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1112"
name = "Modify Registry"
reference = "https://attack.mitre.org/techniques/T1112/"
[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"
[[threat]]
framework = "MITRE ATT&CK"
[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"
[internal]
min_endpoint_version = "8.1.0"