Analytics Story: Hermetic Wiper
Description
This analytic story contains detections that allow security analysts to detect and investigate unusual activities that might relate to the destructive malware targeting Ukrainian organizations also known as "Hermetic Wiper". This analytic story looks for abuse of Regsvr32, executables written in administrative SMB Share, suspicious processes, disabling of memory crash dump and more.
Why it matters
Hermetic Wiper is destructive malware operation found by Sentinel One targeting multiple organizations in Ukraine. This malicious payload corrupts Master Boot Records, uses signed drivers and manipulates NTFS attributes for file destruction.
Detections
| Name ▲▼ |
Technique ▲▼ |
Type ▲▼ |
| Executable File Written in Administrative SMB Share |
SMB/Windows Admin Shares |
TTP |
| Powershell Fileless Script Contains Base64 Encoded Content |
Obfuscated Files or Information, PowerShell |
TTP |
| Executables Or Script Creation In Suspicious Path |
Masquerading |
Anomaly |
| Kerberoasting spn request with RC4 encryption |
Kerberoasting |
TTP |
| Powershell Execute COM Object |
PowerShell, Component Object Model Hijacking |
TTP |
| CMD Carry Out String Command Parameter |
Windows Command Shell |
Hunting |
| Web or Application Server Spawning a Shell |
External Remote Services, Exploit Public-Facing Application |
TTP |
| Windows File Download Via PowerShell |
PowerShell, Ingress Tool Transfer |
Anomaly |
| Screensaver Event Trigger Execution |
Screensaver |
TTP |
| Possible Lateral Movement PowerShell Spawn |
Distributed Component Object Model, Windows Remote Management, Windows Management Instrumentation, Scheduled Task, PowerShell, MMC, Windows Service |
Anomaly |
| Powershell Enable SMB1Protocol Feature |
Indicator Removal from Tools |
TTP |
| WMI Recon Running Process Or Services |
Gather Victim Host Information |
Anomaly |
| Malicious PowerShell Process With Obfuscation Techniques |
PowerShell |
TTP |
| Executables Or Script Creation In Temp Path |
Masquerading |
Anomaly |
| Regsvr32 Silent and Install Param Dll Loading |
Regsvr32 |
Anomaly |
| Suspicious Email Attachment Extensions |
Spearphishing Attachment |
Anomaly |
| Set Default PowerShell Execution Policy To Unrestricted or Bypass |
PowerShell |
TTP |
| Time Provider Persistence Registry |
Time Providers |
TTP |
| Child Processes of Spoolsv exe |
Exploitation for Privilege Escalation |
TTP |
| Windows Modify Show Compress Color And Info Tip Registry |
Modify Registry |
TTP |
| Powershell Processing Stream Of Data |
PowerShell |
Anomaly |
| Windows Disable Memory Crash Dump |
Data Destruction |
TTP |
| Registry Keys Used For Privilege Escalation |
Image File Execution Options Injection |
TTP |
| Recon Using WMI Class |
PowerShell, Gather Victim Host Information |
Anomaly |
| Detect Mimikatz With PowerShell Script Block Logging |
OS Credential Dumping, PowerShell |
TTP |
| Windows Raw Access To Disk Volume Partition |
Disk Structure Wipe |
Anomaly |
| Powershell Fileless Process Injection via GetProcAddress |
Process Injection, PowerShell |
TTP |
| Unloading AMSI via Reflection |
PowerShell, Disable or Modify Tools |
TTP |
| MSI Module Loaded by Non-System Binary |
DLL |
Hunting |
| Windows New Default File Association Value Set |
Change Default File Association |
Hunting |
| PowerShell Domain Enumeration |
PowerShell |
Anomaly |
| Overwriting Accessibility Binaries |
Accessibility Features |
TTP |
| Runas Execution in CommandLine |
Token Impersonation/Theft |
Hunting |
| Active Setup Registry Autostart |
Active Setup |
TTP |
| PowerShell - Connect To Internet With Hidden Window |
PowerShell |
Hunting |
| PowerShell Loading DotNET into Memory via Reflection |
PowerShell |
Anomaly |
| ETW Registry Disabled |
Trusted Developer Utilities Proxy Execution, Disable or Modify Tools |
TTP |
| Recon AVProduct Through Pwh or WMI |
Gather Victim Host Information |
TTP |
| Detect Empire with PowerShell Script Block Logging |
PowerShell |
TTP |
| PowerShell 4104 Hunting |
PowerShell |
Hunting |
| Email Attachments With Lots Of Spaces |
Masquerade File Type, Spearphishing Attachment |
Anomaly |
| Powershell Using memory As Backing Store |
PowerShell |
TTP |
| Windows Suspicious Process File Path |
Match Legitimate Resource Name or Location, Create or Modify System Process |
TTP |
| Windows File Without Extension In Critical Folder |
Data Destruction |
Anomaly |
| Malicious PowerShell Process - Encoded Command |
Obfuscated Files or Information |
Hunting |
| Print Processor Registry Autostart |
Print Processors |
TTP |
| Windows Raw Access To Master Boot Record Drive |
Disk Structure Wipe |
TTP |
| Logon Script Event Trigger Execution |
Logon Script (Windows) |
TTP |
Data Sources
References
Source: GitHub | Version: 2