Windows file indicators for Octopus Scanner malware artifacts

Alerts on Windows file activity for Octopus Scanner-related filenames (Cache134.dat, ExplorerSync.db) in AppData.

FreeReviewedSigma · High · v2
Product
windows
Category
file_event
Author
NVISO (SigmaHQ), DRL 1.1
Published
2020-06-09
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule matches Windows file events where the target filename ends with specific artifact paths associated with Octopus Scanner malware. Attackers and malicious installers may use these files during initial access or execution, making their presence a strong indicator of compromise. The detection relies on Windows file event telemetry that records the target filename for filesystem activity.

Related detections9 linkedT1195.001 — drag to rearrange
Malicious TeamPCP systemd User Unit Dropper via sysmon.py Persistence (via file_event)
Suspicious Python Startup .pth File Creation for Interpreter Persistence
Malicious Backdoored liblzma XZ Utils Library File via file_event
Suspicious SSH Daemon Spawning Shell via xz Backdoor (via process_creation)
Suspicious XZ Utils Backdoor Kill-Switch Environment String via process_creation
Malicious PyPI Package Installation from Gleaming Pisces Supply Chain (via process_creation)
Malicious TeamPCP LiteLLM .pth Startup Hook and Payload Dropper (via file_event)
Malicious Backdoored liblzma Loaded by sshd (CVE-2024-3094)
GitHub Audit: Dependabot Alerts and Security Updates Disabled
Windows file indicators for Octopus Scanner malware artifacts
Pivot detection · T1195.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.