Detection rules › Sigma

PUA - CleanWipe Execution

Status
test
Severity
high
Log source
product windows, category process_creation
Author
Nasreddine Bencherchali (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects the use of CleanWipe a tool usually used to delete Symantec antivirus.

MITRE ATT&CK coverage

TacticTechniques
Defense ImpairmentT1685 Disable or Modify Tools

Event coverage

Rule body yaml

title: PUA - CleanWipe Execution
id: f44800ac-38ec-471f-936e-3fa7d9c53100
status: test
description: Detects the use of CleanWipe a tool usually used to delete Symantec antivirus.
references:
    - https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Other/CleanWipe
author: Nasreddine Bencherchali (Nextron Systems)
date: 2021-12-18
modified: 2023-02-14
tags:
    - attack.defense-impairment
    - attack.t1685
logsource:
    category: process_creation
    product: windows
detection:
    selection1:
        Image|endswith: '\SepRemovalToolNative_x64.exe'
    selection2:
        Image|endswith: '\CATClean.exe'
        CommandLine|contains: '--uninstall'
    selection3:
        Image|endswith: '\NetInstaller.exe'
        CommandLine|contains: '-r'
    selection4:
        Image|endswith: '\WFPUnins.exe'
        CommandLine|contains|all:
            - '/uninstall'
            - '/enterprise'
    condition: 1 of selection*
falsepositives:
    - Legitimate administrative use (Should be investigated either way)
level: high

Stages and Predicates

Stage 0: condition

1 of selection*

Stage 1: selection1

selection1:
    Image|endswith: '\SepRemovalToolNative_x64.exe'

Stage 2: selection2

selection2:
    Image|endswith: '\CATClean.exe'
    CommandLine|contains: '--uninstall'

Stage 3: selection3

selection3:
    Image|endswith: '\NetInstaller.exe'
    CommandLine|contains: '-r'

Stage 4: selection4

selection4:
    Image|endswith: '\WFPUnins.exe'
    CommandLine|contains|all:
        - '/uninstall'
        - '/enterprise'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
CommandLinematch
  • --uninstall
  • -r corpus 13 (sigma 9, kusto 4)
  • /enterprise
  • /uninstall
Imageends_with
  • \CATClean.exe
  • \NetInstaller.exe
  • \SepRemovalToolNative_x64.exe
  • \WFPUnins.exe