Potential CVE-2023-36884 Exploitation - File Downloads


Description

Detects files seen being requested by RomCom while potentially exploiting CVE-2023-36884

Query · sigma

selection:
  cs-method: GET
  c-uri|contains:
  - /ex001.url
  - /file001.search-ms
  - /file001.url
  - /file001.vbs
  - /file1.mht
  - /o2010.asp
  - /redir_obj.html
  - /RFile.asp
  - /zip_k.asp
  - /zip_k2.asp
  - /zip_k3.asp
condition: selection

Known false positives

  • Unknown
Raw source Potential CVE-2023-36884 Exploitation - File Downloads · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Potential CVE-2023-36884 Exploitation - File Downloads
id: 6af1617f-c179-47e3-bd66-b28034a1052d
status: test
description: Detects files seen being requested by RomCom while potentially exploiting CVE-2023-36884
references:
    - https://blogs.blackberry.com/en/2023/07/romcom-targets-ukraine-nato-membership-talks-at-nato-summit
author: X__Junior
date: 2023-07-12
tags:
    - attack.command-and-control
    - cve.2023-36884
    - detection.emerging-threats
logsource:
    category: proxy
detection:
    selection:
        cs-method: 'GET'
        c-uri|contains:
            - '/ex001.url'
            - '/file001.search-ms'
            - '/file001.url'
            - '/file001.vbs'
            - '/file1.mht'
            - '/o2010.asp'
            - '/redir_obj.html'
            - '/RFile.asp'
            - '/zip_k.asp'
            - '/zip_k2.asp'
            - '/zip_k3.asp'
    condition: selection
falsepositives:
    - Unknown
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.