Detection rules › Splunk

Process Connection to Mega - Windows (Sysmon)

Group by
_time, host
Source
github.com/anvilogic-forge/armory

Mega is a cloud storage service used by many threat actors due to its use of end-to-end encryption and semi-anonymous payment options. The client application MEGAsync.exe and command-line interface utility MegaCMD allow threat actors to exfiltrate large amounts of data. This use case detects network connections involving MEGASync.exe or MegaCMD or network connections to mega.co.nz or mega.nz (Sysmon only).

MITRE ATT&CK coverage

TacticTechniques
Exfiltration

References

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 3: Network connection

Rule body

id: '35864.62856'
title: Process Connection to Mega - Windows
description: Mega is a cloud storage service used by many threat actors due to its
  use of end-to-end encryption and semi-anonymous payment options. The client application
  MEGAsync.exe and command-line interface utility MegaCMD allow threat actors to exfiltrate
  large amounts of data. This use case detects network connections involving MEGASync.exe
  or MegaCMD or network connections to mega.co.nz or mega.nz (Sysmon only).
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=3) OR "<EventID>3<")
  "Megasync.exe" OR "megacmd" OR "mega.co.nz" OR "mega.nz" | where match(dest_host,
  "(?i)mega\.(co\.)?nz") or match(process_name, "(?i)mega(sync|cmd)") | table _time,
  host, user, process, process_*, parent_process_*, dest_host | bin span=300s | stats
  values(*) as * by _time, host '
techniques:
- exfiltration:exfiltration over web service
technique_id: 
- T1567
data_category:
- Windows Sysmon
- Process use of network
references:
- https://redcanary.com/blog/threat-detection/rclone-mega-extortion/

Stages and Predicates

Stage 1: search

`get_endpoint_data` `get_endpoint_data_sysmon` (TERM(EventCode=3) OR "<EventID>3<") "Megasync.exe" OR "megacmd" OR "mega.co.nz" OR "mega.nz"

Stage 2: where

| where match(dest_host, "(?i)mega\.(co\.)?nz") or match(process_name, "(?i)mega(sync|cmd)")

Stage 3: table

| table _time, host, user, process, process_*, parent_process_*, dest_host

Stage 4: bucket

| bin span=300s

Stage 5: stats

| stats values(*) as * by _time, host

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
EventCodeeq
  • 3 corpus 24 (splunk 14, kusto 8, chronicle 2)
field:"EventID" kind:eq value:"3"
dest_hostregex_match
  • "(?i)mega.(co.)?nz"
field:"dest_host" kind:regex_match
process_nameregex_match
  • "(?i)mega(sync|cmd)" corpus 2 (splunk 2)
field:"process_name" kind:regex_match

Search terms

These SPL tokens match against raw event text.

StageTerm
1"<EventID>3<"
1"Megasync.exe"
1"megacmd"
1"mega.co.nz"
1"mega.nz"