CVE-2024-50623 Exploitation Attempt - Cleo
Description
Detects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.
Query · sigma
selection: ParentImage|endswith: \javaw.exe ParentCommandLine|contains: - Harmony - lexicom - VersaLex - VLTrader Image|endswith: \cmd.exe CommandLine|contains: - powershell - ' -enc ' - ' -EncodedCommand' - .Download condition: selection
Known false positives
- Unlikely