+++
Introduction Hello everyone and welcome back to the next post in our Detection Engineering series. In the last post, we started getting our feet wet with detection engineering by reading through a Cisco Talos report on Chaos ransomware’s msaRAT and creating a couple Sigma rules from the activity described in the report. We made one rule for the suspicious curl.exe command used to download the malware and another for Chrome or Edge launching in headless mode with the Chrome DevTools Protocol enabled.
Introduction Hello everyone and welcome back to another post from yours truly. Today we’re going to be doing something slightly different actually. I’ve been looking more into detection engineering recently and been wanting to get better at writing detection rules in different formats and whatnot. So today we’re going to be actually looking at a threat intelligence post from Cisco Talos covering some malware from the Chaos ransomware group. Specifically, their msaRAT malware that uses the browser for its C2 communications.
Writeup I’m not gonna lie to you, this one had me stumped for quite a few days, but as per the usual with these things the answer was kinda in my face if I just had dug a little deeper. So let’s go ahead and dig into CBC Task 2. Okay, so the disk image we were looking at last task definitely had some malware installed on the “endpoint” and that malware was generating some network traffic.