Detection rules › Sigma

HackTool - Quarks PwDump Execution

Status
test
Severity
high
Log source
product windows, category process_creation
Author
Nasreddine Bencherchali (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects usage of the Quarks PwDump tool via commandline arguments

MITRE ATT&CK coverage

Event coverage

Rule body yaml

title: HackTool - Quarks PwDump Execution
id: 0685b176-c816-4837-8e7b-1216f346636b
status: test
description: Detects usage of the Quarks PwDump tool via commandline arguments
references:
    - https://github.com/quarkslab/quarkspwdump
    - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/seedworm-apt-iran-middle-east
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-09-05
modified: 2023-02-05
tags:
    - attack.credential-access
    - attack.t1003.002
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        Image|endswith: '\QuarksPwDump.exe'
    selection_cli:
        CommandLine:
            - ' -dhl'
            - ' --dump-hash-local'
            - ' -dhdc'
            - ' --dump-hash-domain-cached'
            - ' --dump-bitlocker'
            - ' -dhd '
            - ' --dump-hash-domain '
            - '--ntds-file'
    condition: 1 of selection_*
falsepositives:
    - Unlikely
level: high

Stages and Predicates

Stage 0: condition

1 of selection_*

Stage 1: selection_img

selection_img:
    Image|endswith: '\QuarksPwDump.exe'

Stage 2: selection_cli

selection_cli:
    CommandLine:
        - ' -dhl'
        - ' --dump-hash-local'
        - ' -dhdc'
        - ' --dump-hash-domain-cached'
        - ' --dump-bitlocker'
        - ' -dhd '
        - ' --dump-hash-domain '
        - '--ntds-file'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
CommandLineeq
  • --dump-bitlocker
  • --dump-hash-domain
  • --dump-hash-domain-cached
  • --dump-hash-local
  • -dhd
  • -dhdc
  • -dhl
  • --ntds-file
Imageends_with
  • \QuarksPwDump.exe corpus 2 (sigma 2)