ScreenConnect - SlashAndGrab Exploitation Indicators
Description
Detects indicators of exploitation by threat actors during exploitation of the "SlashAndGrab" vulnerability related to ScreenConnect as reported Team Huntress
Query · sigma
selection: - TargetFilename|contains|all: - C:\Windows\Temp\ScreenConnect\ - \LB3.exe - TargetFilename|contains: - C:\mpyutd.msi - C:\perflogs\RunSchedulerTaskOnce.ps1 - C:\ProgramData\1.msi - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\mpyutd.msi - C:\ProgramData\update.dat - C:\Users\oldadmin\Documents\MilsoftConnect\Files\ta.exe - C:\Windows\Help\Help\SentinelAgentCore.dll - C:\Windows\Help\Help\SentinelUI.exe - C:\Windows\spsrv.exe - C:\Windows\Temp\svchost.exe condition: selection
Known false positives
- Unknown