Windows File Event Indicators of MOVEit Transfer CVE-2023-34362 Exploitation Artifacts

Finds MOVEit Transfer webroot file and ASP.NET compilation artifacts on Windows that may indicate CVE-2023-34362 exploitation.

FreeUnreviewedSigmahighv1
title: Windows File Event Indicators of MOVEit Transfer CVE-2023-34362 Exploitation Artifacts
id: 77545ec2-ec05-42d6-a497-9402e47c3ca9
status: test
description: This rule looks for Windows file creation or modification activity consistent with potential MOVEit Transfer CVE-2023-34362 exploitation. It matches file paths under MOVEit Transfer wwwroot as well as specific known indicator filenames and compiled ASP.NET artifacts created during 2023-03 through 2023-06. The behavior matters because successful exploitation can involve deployment or staging of malicious files within the webroot and generation of transient ASP.NET application assemblies. Telemetry relies on file_event data including TargetFilename and CreationUtcTime.
references:
  - https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/
  - https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
  - https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/
  - https://www.reddit.com/r/sysadmin/comments/13wxuej/comment/jmhdg55/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Exploits/CVE-2023-34362-MOVEit-Transfer-Exploit/file_event_win_exploit_cve_2023_34362_moveit_transfer.yml
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-01
modified: 2024-08-13
tags:
  - attack.initial-access
  - attack.t1190
  - cve.2023-34362
  - detection.emerging-threats
logsource:
  category: file_event
  product: windows
detection:
  selection_generic:
    TargetFilename|contains:
      - \MOVEit Transfer\wwwroot\
      - \MOVEitTransfer\wwwroot\
    TargetFilename|endswith:
      - .7z
      - .bat
      - .dll
      - .exe
      - .ps1
      - .rar
      - .vbe
      - .vbs
      - .zip
  selection_known_ioc:
    TargetFilename|endswith:
      - \MOVEit Transfer\wwwroot\_human2.aspx.lnk
      - \MOVEit Transfer\wwwroot\_human2.aspx
      - \MOVEit Transfer\wwwroot\human2.aspx.lnk
      - \MOVEit Transfer\wwwroot\human2.aspx
      - \MOVEitTransfer\wwwroot\_human2.aspx.lnk
      - \MOVEitTransfer\wwwroot\_human2.aspx
      - \MOVEitTransfer\wwwroot\human2.aspx.lnk
      - \MOVEitTransfer\wwwroot\human2.aspx
  selection_compiled_asp:
    CreationUtcTime|startswith:
      - "2023-03- "
      - "2023-04- "
      - "2023-05- "
      - "2023-06- "
    TargetFilename|contains|all:
      - \Windows\Microsoft.net\Framework64\v
      - \Temporary ASP.NET Files\
      - App_Web_
    TargetFilename|endswith: .dll
  condition: 1 of selection_*
falsepositives:
  - To avoid FP, this rule should only be applied on MOVEit servers.
level: high
license: DRL-1.1
related:
  - id: c3b2a774-3152-4989-83c1-7afc48fd1599
    type: derived

What it detects

This rule looks for Windows file creation or modification activity consistent with potential MOVEit Transfer CVE-2023-34362 exploitation. It matches file paths under MOVEit Transfer wwwroot as well as specific known indicator filenames and compiled ASP.NET artifacts created during 2023-03 through 2023-06. The behavior matters because successful exploitation can involve deployment or staging of malicious files within the webroot and generation of transient ASP.NET application assemblies. Telemetry relies on file_event data including TargetFilename and CreationUtcTime.

Known false positives

  • To avoid FP, this rule should only be applied on MOVEit servers.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.