Suspicious Wav File In Appdata Folder

Suspicious Wav File In Appdata Folder


This analytic is to detect a suspicious creation of .wav file in appdata folder. This behavior was seen in Remcos RAT malware where it put the audio recording in the appdata\audio folde as part of data collection. this recording can be send to its C2 server as part of its exfiltration to the compromised machine. creation of wav files in this folder path is not a ussual disk place used by user to save audio format file.


Suspicious Wav File In Appdata Folder Help

To successfully implement this search, you need to be ingesting logs with the process name, parent process, filename, filepath and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.


Open in Search