CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
Description
Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
Query · sigma
selection: TargetFilename|contains: - C:\Windows\system32\physmem.sys - C:\Windows\System32\IME\IMEJP\imjpueact.dll - C:\Windows\system32\ime\IMETC\IMTCPROT.DLL - C:\Windows\system32\ime\SHARED\imecpmeid.dll - C:\Windows\system32\config\spp\ServiceState\Recovery\pac.dat - C:\Windows\system32\config\cy-GB\Setup\SKB\InputMethod\TupTask.dat - C:\Windows\system32\config\config\startwus.dat - C:\Windows\system32\ime\SHARED\WimBootConfigurations.ini - C:\Windows\system32\ime\IMEJP\WimBootConfigurations.ini - C:\Windows\system32\ime\IMETC\WimBootConfigurations.ini condition: selection
Known false positives
- Unlikely