Remcos RAT INETCookies File Deletion


Description

Identifies INETCookies file deletion by unsigned process, consistent with the Remcos Remote Access Trojan (RAT) behavior. Remcos RAT is used by attackers to perform actions on infected machines remotely.

Query · eql

file where event.action == "deletion" and file.name : "container.dat" and user.id != "S-1-5-18" and
 (process.code_signature.trusted == false or process.code_signature.exists == false) and
 file.path : "?:\\Users\\*\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\container.dat" and
 not process.executable : "C:\\Program Files (x86)\\WinDirStat\\windirstat.exe"
Raw source Remcos RAT INETCookies File Deletion · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies INETCookies file deletion by unsigned process, consistent with the Remcos Remote Access Trojan (RAT)
behavior. Remcos RAT is used by attackers to perform actions on infected machines remotely.
"""
id = "cf7592cc-6954-4973-92ee-213c5eea0fa5"
license = "Elastic License v2"
name = "Remcos RAT INETCookies File Deletion"
os_list = ["windows"]
reference = [
    "https://any.run/malware-trends/remcos",
    "https://attack.mitre.org/software/S0332/",
    "https://www.elastic.co/security-labs/dissecting-remcos-rat-part-four",
]
version = "1.0.4"

query = '''
file where event.action == "deletion" and file.name : "container.dat" and user.id != "S-1-5-18" and
 (process.code_signature.trusted == false or process.code_signature.exists == false) and
 file.path : "?:\\Users\\*\\AppData\\Local\\Microsoft\\Windows\\INetCookies\\container.dat" and
 not process.executable : "C:\\Program Files (x86)\\WinDirStat\\windirstat.exe"
'''

min_endpoint_version = "8.1.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1112"
name = "Modify Registry"
reference = "https://attack.mitre.org/techniques/T1112/"


[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"
[[threat]]
framework = "MITRE ATT&CK"

[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"

[internal]
min_endpoint_version = "8.1.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.