Neo23x0/Loki

Core 210 keylogging file maybe a false positive

Q7ak5 opened this issue · 0 comments

Q7ak5 commented

Two alerts were triggered with score 210 (may indicating a keylogger) and score 100. The last one is most likely a false positive. However, I would appreciate your comment with score 210, I am not sure about it, because the file found with score 210 is just a log file. No other IoC were found. The scan results:

Alert Filescan Malicious file found
FILE: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REINER SCT cyberJack\Support.url SCORE: 100
MD5: 521cb9865a2ae7c486b08c1f55a9a8cd
SHA1: 40ce013d509d0721d0080fad14522c65f07a779f
SHA256: af61323408be68937d1ae774dfd3b41943fda5e209a1a64e81f061bcccb57dcf
SIZE: 156 TYPE: UNKNOWN FIRSTBYTES: 5b496e7465726e657453686f72746375745d0d0a / [InternetShortcut]
CREATED: 2019-12-30T22:29:08Z MODIFIED: 2019-12-30T22:29:08Z ACCESSED: 2019-12-30T22:29:08Z EXT: .url
REASON_1: YARA rule Methodology_Suspicious_Shortcut_SMB_URL / Detects remote SMB path for .URL persistence MATCHED_1: Str1: "URL=file://C" Str2: "[InternetShortcut]" SUBSCORE_1: 50 REF_1: https://twitter.com/cglyer/status/1176184798248919044
REASON_2: YARA rule Methodology_Suspicious_Shortcut_IconNotFromExeOrDLLOrICO / Detects possible shortcut usage for .URL persistence MATCHED_2: Str1: "IconFile=" Str2: "[InternetShortcut]" SUBSCORE_2: 50 REF_2: https://twitter.com/ItsReallyNick/status/1176229087196696577

Alert LogScan Malicious log entry found SCORE: 210 DESC: HP Keylogging Audio Driver https://goo.gl/BSQWzw / HP Keylogging Audio Driver https://goo.gl/BSQWzw / HP Keylogging Audio Driver https://goo.gl/BSQWzw ELEMENT: 7.200.0.2 : 20:37:21.300 : pszFileToDelete = C:\Users\Public\MicTray.log, dwFlags = 2 OBJECT: C:\ProgramData\UIU\InstallerLogs\MicTray\x64\UIU_INSTALL64.Setup64exe.LOG MATCHED_STRINGS: \Users\Public\MicTray.log / \Users\Public\MicTray.log / \Users\Public\MicTray.log

I appreciate your comment!