Hermetic Wiper TG Process Patterns
Description
Detects process execution patterns found in intrusions related to the Hermetic Wiper malware attacks against Ukraine in February 2022
Query · sigma
selection1: Image|endswith: \policydefinitions\postgresql.exe selection2: - CommandLine|contains: - CSIDL_SYSTEM_DRIVE\temp\sys.tmp - ' 1> \\\\127.0.0.1\ADMIN$\__16' - CommandLine|contains|all: - 'powershell -c ' - '\comsvcs.dll MiniDump ' - \winupd.log full condition: 1 of selection*
Known false positives
- Unknown