Windows File Event Indicators of MOVEit Transfer CVE-2023-34362 Exploitation Artifacts
Finds MOVEit Transfer webroot file and ASP.NET compilation artifacts on Windows that may indicate CVE-2023-34362 exploitation.
FreeUnreviewedSigmahighv1
windows-file-event-indicators-of-moveit-transfer-cve-2023-34362-exploitation-art-c3b2a774
title: Windows File Event Indicators of MOVEit Transfer CVE-2023-34362 Exploitation Artifacts
id: 77545ec2-ec05-42d6-a497-9402e47c3ca9
status: test
description: This rule looks for Windows file creation or modification activity consistent with potential MOVEit Transfer CVE-2023-34362 exploitation. It matches file paths under MOVEit Transfer wwwroot as well as specific known indicator filenames and compiled ASP.NET artifacts created during 2023-03 through 2023-06. The behavior matters because successful exploitation can involve deployment or staging of malicious files within the webroot and generation of transient ASP.NET application assemblies. Telemetry relies on file_event data including TargetFilename and CreationUtcTime.
references:
- https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/
- https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
- https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/
- https://www.reddit.com/r/sysadmin/comments/13wxuej/comment/jmhdg55/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-34362-MOVEit-Transfer-Exploit/file_event_win_exploit_cve_2023_34362_moveit_transfer.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-01
modified: 2024-08-13
tags:
- attack.initial-access
- attack.t1190
- cve.2023-34362
- detection.emerging-threats
logsource:
category: file_event
product: windows
detection:
selection_generic:
TargetFilename|contains:
- \MOVEit Transfer\wwwroot\
- \MOVEitTransfer\wwwroot\
TargetFilename|endswith:
- .7z
- .bat
- .dll
- .exe
- .ps1
- .rar
- .vbe
- .vbs
- .zip
selection_known_ioc:
TargetFilename|endswith:
- \MOVEit Transfer\wwwroot\_human2.aspx.lnk
- \MOVEit Transfer\wwwroot\_human2.aspx
- \MOVEit Transfer\wwwroot\human2.aspx.lnk
- \MOVEit Transfer\wwwroot\human2.aspx
- \MOVEitTransfer\wwwroot\_human2.aspx.lnk
- \MOVEitTransfer\wwwroot\_human2.aspx
- \MOVEitTransfer\wwwroot\human2.aspx.lnk
- \MOVEitTransfer\wwwroot\human2.aspx
selection_compiled_asp:
CreationUtcTime|startswith:
- "2023-03- "
- "2023-04- "
- "2023-05- "
- "2023-06- "
TargetFilename|contains|all:
- \Windows\Microsoft.net\Framework64\v
- \Temporary ASP.NET Files\
- App_Web_
TargetFilename|endswith: .dll
condition: 1 of selection_*
falsepositives:
- To avoid FP, this rule should only be applied on MOVEit servers.
level: high
license: DRL-1.1
related:
- id: c3b2a774-3152-4989-83c1-7afc48fd1599
type: derived
What it detects
This rule looks for Windows file creation or modification activity consistent with potential MOVEit Transfer CVE-2023-34362 exploitation. It matches file paths under MOVEit Transfer wwwroot as well as specific known indicator filenames and compiled ASP.NET artifacts created during 2023-03 through 2023-06. The behavior matters because successful exploitation can involve deployment or staging of malicious files within the webroot and generation of transient ASP.NET application assemblies. Telemetry relies on file_event data including TargetFilename and CreationUtcTime.
Known false positives
- To avoid FP, this rule should only be applied on MOVEit servers.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.