Detection rules › Splunk
Process Connection to Mega - Windows (Windows Event Log)
Mega is a cloud storage service used by many threat actors due to its use of end-to-end encryption and semi-anonymous payment options. The client application MEGAsync.exe and command-line interface utility MegaCMD allow threat actors to exfiltrate large amounts of data. This use case detects network connections involving MEGASync.exe or MegaCMD or network connections to mega.co.nz or mega.nz (Sysmon only).
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Exfiltration |
References
Telemetry coverage
| Provider | Record / event type |
|---|---|
| Security-Auditing | Event ID 5156: The Windows Filtering Platform has permitted a connection. |
Rule body
id: '35864.62857'
title: Process Connection to Mega - Windows
description: Mega is a cloud storage service used by many threat actors due to its
use of end-to-end encryption and semi-anonymous payment options. The client application
MEGAsync.exe and command-line interface utility MegaCMD allow threat actors to exfiltrate
large amounts of data. This use case detects network connections involving MEGASync.exe
or MegaCMD or network connections to mega.co.nz or mega.nz (Sysmon only).
logic_format: Splunk
logic: '`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=5156) OR
"<EventID>5156<") "Megasync.exe" OR "megacmd" | where match(process_name, "(?i)mega(sync|cmd)")
| table _time, host, user, process, process_*, parent_process_*, dest_host | bin
span=300s | stats values(*) as * by _time, host '
techniques:
- exfiltration:exfiltration over web service
technique_id:
- T1567
data_category:
- Windows event logs
- Process use of network
references:
- https://redcanary.com/blog/threat-detection/rclone-mega-extortion/
Stages and Predicates
Stage 1: search
`get_endpoint_data` `get_endpoint_data_winevent` (TERM(EventCode=5156) OR "<EventID>5156<") "Megasync.exe" OR "megacmd"
Stage 2: where
| where match(process_name, "(?i)mega(sync|cmd)")
Stage 3: table
| table _time, host, user, process, process_*, parent_process_*, dest_host
Stage 4: bucket
| bin span=300s
Stage 5: stats
| stats values(*) as * by _time, host
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
EventCode | eq |
| field:"EventID" kind:eq value:"5156" |
process_name | regex_match |
| field:"process_name" kind:regex_match |
Search terms
These SPL tokens match against raw event text.
| Stage | Term |
|---|---|
| 1 | "<EventID>5156<" |
| 1 | "Megasync.exe" |
| 1 | "megacmd" |