Skip to content

Commit dc38804

Browse files
Merge PR SigmaHQ#5863 from @swachchhanda000 - Add finger.exe to related rules
update: Potential Defense Evasion Via Rename Of Highly Relevant Binaries - add finger.exe update: System File Execution Location Anomaly - add finger.exe
1 parent 14d11fd commit dc38804

2 files changed

Lines changed: 6 additions & 2 deletions

File tree

rules/windows/process_creation/proc_creation_win_renamed_binary_highly_relevant.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,10 @@ references:
1919
- https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/megacortex-ransomware-spotted-attacking-enterprise-networks
2020
- https://twitter.com/christophetd/status/1164506034720952320
2121
- https://threatresearch.ext.hp.com/svcready-a-new-loader-reveals-itself/
22+
- https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke
2223
author: Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113
2324
date: 2019-06-15
24-
modified: 2024-12-03
25+
modified: 2026-02-12
2526
tags:
2627
- attack.defense-evasion
2728
- attack.t1036.003
@@ -41,6 +42,7 @@ detection:
4142
- 'cmstp.exe'
4243
- 'cscript.exe'
4344
- 'IE4UINIT.EXE'
45+
- 'finger.exe'
4446
- 'mshta.exe'
4547
- 'msiexec.exe'
4648
- 'msxsl.exe'
@@ -62,6 +64,7 @@ detection:
6264
- '\cmstp.exe'
6365
- '\cscript.exe'
6466
- '\ie4uinit.exe'
67+
- '\finger.exe'
6568
- '\mshta.exe'
6669
- '\msiexec.exe'
6770
- '\msxsl.exe'

rules/windows/process_creation/proc_creation_win_susp_system_exe_anomaly.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ references:
1212
- https://www.splunk.com/en_us/blog/security/inno-setup-malware-redline-stealer-campaign.html
1313
author: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems)
1414
date: 2017-11-27
15-
modified: 2025-11-23
15+
modified: 2026-02-12
1616
tags:
1717
- attack.defense-evasion
1818
- attack.t1036
@@ -41,6 +41,7 @@ detection:
4141
- '\dllhst3g.exe'
4242
- '\dwm.exe'
4343
- '\eventvwr.exe'
44+
- '\finger.exe'
4445
- '\logonui.exe'
4546
- '\LsaIso.exe'
4647
- '\lsass.exe'

0 commit comments

Comments
 (0)