Advanced IP Scanner Execution via Windows Temp File Path
Flags file activity targeting Advanced IP Scanner 2 under a Windows user Temp directory.
FreeUnreviewedSigmamediumv1
advanced-ip-scanner-execution-via-windows-temp-file-path-fed85bf9
title: Advanced IP Scanner Execution via Windows Temp File Path
id: 7f0c1851-9e67-4417-a2fb-05ebe0673215
related:
- id: bef37fa2-f205-4a7b-b484-0759bfd5f86f
type: derived
- id: fed85bf9-e075-4280-9159-fbe8a023d6fa
type: derived
status: test
description: This rule identifies file events where the target filename contains the path segment '\AppData\Local\Temp\Advanced IP Scanner 2'. Attackers may use network discovery tools from user-writable locations to identify reachable systems before further actions. It relies on Windows file event telemetry that includes the target filename for the process or operation generating the file event.
references:
- https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/
- https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html
- https://labs.f-secure.com/blog/prelude-to-ransomware-systembc
- https://assets.documentcloud.org/documents/20444693/fbi-pin-egregor-ransomware-bc-01062021.pdf
- https://thedfirreport.com/2021/01/18/all-that-for-a-coinminer
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_advanced_ip_scanner.yml
author: "@ROxPinTeddy, Huntrule Team"
date: 2020-05-12
modified: 2022-11-29
tags:
- attack.discovery
- attack.t1046
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|contains: \AppData\Local\Temp\Advanced IP Scanner 2
condition: selection
falsepositives:
- Legitimate administrative use
level: medium
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_advanced_ip_scanner/info.yml
license: DRL-1.1
What it detects
This rule identifies file events where the target filename contains the path segment '\AppData\Local\Temp\Advanced IP Scanner 2'. Attackers may use network discovery tools from user-writable locations to identify reachable systems before further actions. It relies on Windows file event telemetry that includes the target filename for the process or operation generating the file event.
Known false positives
- Legitimate administrative use
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.