Advanced IP Scanner Execution via Windows Temp File Path

Flags file activity targeting Advanced IP Scanner 2 under a Windows user Temp directory.

FreeUnreviewedSigmamediumv1
title: Advanced IP Scanner Execution via Windows Temp File Path
id: 7f0c1851-9e67-4417-a2fb-05ebe0673215
related:
  - id: bef37fa2-f205-4a7b-b484-0759bfd5f86f
    type: derived
  - id: fed85bf9-e075-4280-9159-fbe8a023d6fa
    type: derived
status: test
description: This rule identifies file events where the target filename contains the path segment '\AppData\Local\Temp\Advanced IP Scanner 2'. Attackers may use network discovery tools from user-writable locations to identify reachable systems before further actions. It relies on Windows file event telemetry that includes the target filename for the process or operation generating the file event.
references:
  - https://news.sophos.com/en-us/2019/12/09/snatch-ransomware-reboots-pcs-into-safe-mode-to-bypass-protection/
  - https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html
  - https://labs.f-secure.com/blog/prelude-to-ransomware-systembc
  - https://assets.documentcloud.org/documents/20444693/fbi-pin-egregor-ransomware-bc-01062021.pdf
  - https://thedfirreport.com/2021/01/18/all-that-for-a-coinminer
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file/file_event/file_event_win_advanced_ip_scanner.yml
author: "@ROxPinTeddy, Huntrule Team"
date: 2020-05-12
modified: 2022-11-29
tags:
  - attack.discovery
  - attack.t1046
logsource:
  category: file_event
  product: windows
detection:
  selection:
    TargetFilename|contains: \AppData\Local\Temp\Advanced IP Scanner 2
  condition: selection
falsepositives:
  - Legitimate administrative use
level: medium
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_advanced_ip_scanner/info.yml
license: DRL-1.1

What it detects

This rule identifies file events where the target filename contains the path segment '\AppData\Local\Temp\Advanced IP Scanner 2'. Attackers may use network discovery tools from user-writable locations to identify reachable systems before further actions. It relies on Windows file event telemetry that includes the target filename for the process or operation generating the file event.

Known false positives

  • Legitimate administrative use

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.