APT_Tick_Sysmon_Loader_Jun18
Description
Detects Sysmon Loader from Tick group incident - Weaponized USB
Query · yara
strings:
$x1 = "SysMonitor_3A2DCB47" fullword ascii
$s1 = "msxml.exe" fullword ascii
$s2 = "wins.log" fullword ascii
$s3 = "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\run" fullword ascii
$s4 = "%2d-%2d-%2d-%2d" fullword ascii
$s5 = "%USERPROFILE%" fullword ascii /* Goodware String - occured 22 times */
$s6 = "Windows NT" fullword ascii /* Goodware String - occured 72 times */
$s7 = "device monitor" fullword ascii
$s8 = "\\Accessories" ascii
condition:
uint16(0) == 0x5a4d and filesize < 200KB and (
pe.imphash() == "c5bb16e79fb500c430edce9481ae5b2b" or
$x1 or 6 of them
)