Greenbug Espionage Group Indicators
Description
Detects tools and process executions used by Greenbug in their May 2020 campaign as reported by Symantec
Query · sigma
selection_img: Image|endswith: - :\ProgramData\adobe\Adobe.exe - :\ProgramData\oracle\local.exe - \revshell.exe - \infopagesbackup\ncat.exe - :\ProgramData\comms\comms.exe selection_msf: CommandLine|contains|all: - -ExecutionPolicy Bypass -File - \msf.ps1 selection_ncat: CommandLine|contains|all: - infopagesbackup - \ncat - -e cmd.exe selection_powershell: CommandLine|contains: - system.Data.SqlClient.SqlDataAdapter($cmd); [void]$da.fill - -nop -w hidden -c $k=new-object - '[Net.CredentialCache]::DefaultCredentials;IEX ' - ' -nop -w hidden -c $m=new-object net.webclient;$m' - -noninteractive -executionpolicy bypass whoami - -noninteractive -executionpolicy bypass netstat -a selection_other: CommandLine|contains: L3NlcnZlcj1 condition: 1 of selection_*
Known false positives
- Unlikely