PUA - CleanWipe Execution


Description

Detects the use of CleanWipe a tool usually used to delete Symantec antivirus.

Query · sigma

selection1:
  Image|endswith: \SepRemovalToolNative_x64.exe
selection2:
  Image|endswith: \CATClean.exe
  CommandLine|contains: --uninstall
selection3:
  Image|endswith: \NetInstaller.exe
  CommandLine|contains: -r
selection4:
  Image|endswith: \WFPUnins.exe
  CommandLine|contains|all:
  - /uninstall
  - /enterprise
condition: 1 of selection*

Known false positives

  • Legitimate administrative use (Should be investigated either way)
Raw source PUA - CleanWipe Execution · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: PUA - CleanWipe Execution
id: f44800ac-38ec-471f-936e-3fa7d9c53100
status: test
description: Detects the use of CleanWipe a tool usually used to delete Symantec antivirus.
references:
    - https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Other/CleanWipe
author: Nasreddine Bencherchali (Nextron Systems)
date: 2021-12-18
modified: 2023-02-14
tags:
    - attack.defense-impairment
    - attack.t1685
logsource:
    category: process_creation
    product: windows
detection:
    selection1:
        Image|endswith: '\SepRemovalToolNative_x64.exe'
    selection2:
        Image|endswith: '\CATClean.exe'
        CommandLine|contains: '--uninstall'
    selection3:
        Image|endswith: '\NetInstaller.exe'
        CommandLine|contains: '-r'
    selection4:
        Image|endswith: '\WFPUnins.exe'
        CommandLine|contains|all:
            - '/uninstall'
            - '/enterprise'
    condition: 1 of selection*
falsepositives:
    - Legitimate administrative use (Should be investigated either way)
level: high

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.