Potential MuddyWater APT Activity


Description

Detects potential Muddywater APT activity

Query · sigma

selection_mshta:
  CommandLine|contains|all:
  - vbscript:Close(Execute("CreateObject(
  - powershell
  - -w 1 -exec Bypass
  - \ProgramData\
selection_survey:
  CommandLine|contains|all:
  - Win32_OperatingSystem
  - Win32_NetworkAdapterConfiguration
  - root\SecurityCenter2
  - '[System.Net.DNS]'
selection_pwsh_backdoor:
  CommandLine|contains|all:
  - '[Convert]::ToBase64String'
  - '[System.Text.Encoding]::UTF8.GetString]'
  - GetResponse().GetResponseStream()
  - '[System.Net.HttpWebRequest]::Create('
  - '-bxor '
condition: 1 of selection_*

Known false positives

  • Unlikely
Raw source Potential MuddyWater APT Activity · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Potential MuddyWater APT Activity
id: 36222790-0d43-4fe8-86e4-674b27809543
status: test
description: Detects potential Muddywater APT activity
references:
    - https://www.mandiant.com/resources/blog/iranian-threat-group-updates-ttps-in-spear-phishing-campaign
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-03-10
tags:
    - attack.execution
    - attack.stealth
    - attack.g0069
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection_mshta:
        CommandLine|contains|all:
            - 'vbscript:Close(Execute("CreateObject('
            - 'powershell'
            - '-w 1 -exec Bypass'
            - '\ProgramData\'
    selection_survey:
        CommandLine|contains|all:
            - 'Win32_OperatingSystem'
            - 'Win32_NetworkAdapterConfiguration'
            - 'root\SecurityCenter2'
            - '[System.Net.DNS]'
    selection_pwsh_backdoor:
        CommandLine|contains|all:
            - '[Convert]::ToBase64String'
            - '[System.Text.Encoding]::UTF8.GetString]'
            - 'GetResponse().GetResponseStream()'
            - '[System.Net.HttpWebRequest]::Create('
            - '-bxor '
    condition: 1 of selection_*
falsepositives:
    - Unlikely
level: high

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.