{"_index": "wazuh-alerts-3.x-2018.01.29","_type": "wazuh","_id": "BzgjQGEBLKqaiyQC9zmD","_version": 1,"_score": null,"_source": {"rule": {"mail": false,"level": 9,"description": "Windows malware detected.","firedtimes": 1,"pci_dss": ["11.4"],"groups": ["ossec","rootcheck","gpg13_4.2"],"id": "513"},"full_log": "Windows Malware: Possible Malware - Svchost running outside system32 {PCI_DSS: 11.4}. Process: C:\\Windows\\system32\\svchost.exe.","path": "/var/ossec/logs/alerts/alerts.json","data": {"title": "Windows Malware: Possible Malware - Svchost running outside system32"},"agent": {"name": "vWin7-32","id": "011"},"decoder": {"name": "rootcheck"},"host": "wazuh-server","location": "rootcheck","@timestamp": "2018-01-29T04:19:13.000Z","manager": {"name": "wazuh-server"},"id": "1517199553.140529"},"fields": {"@timestamp": ["2018-01-29T04:19:13.000Z"]},"highlight": {"manager.name": ["@kibana-highlighted-field@wazuh-server@/kibana-highlighted-field@"],"rule.pci_dss": ["@kibana-highlighted-field@11.4@/kibana-highlighted-field@"],"agent.name": ["@kibana-highlighted-field@vWin7-32@/kibana-highlighted-field@"],"full_log": ["Windows Malware: Possible Malware - Svchost running outside @kibana-highlighted-field@system32@/kibana-highlighted-field@ {PCI_DSS: 11.4}.","Process: C:\\Windows\\@kibana-highlighted-field@system32@/kibana-highlighted-field@\\svchost.exe."]},"sort": [1517199553000]}
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/ce7402bb-401d-40bb-b3d1-319911854fe5%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
[Possible Malware - Svchost running outside system32 {PCI_DSS: 11.4}] [all] []
p:r:svchost.exe && !%WINDIR%\System32\svchost.exe;
f:!%WINDIR%\System32;
[Possible Malware - Svchost running outside system32 {PCI_DSS: 11.4}] [all] []
p:r:svchost.exe && !%WINDIR%\Sysnative\svchost.exe;
f:!%WINDIR%\SysWOW64;Enter code here...
In case the windows agent performs malware scans at boot up I rebooted one 32-bit windows 7 system (vWin7-32) and one 64-bit windows 10 system (vWin10-64) after making the change I described in my last entry to var/ossec/etc/shared/default/win_malware_rcl.txt on the system running wazuh-manager.I have so far (~25 minutes) received no malware reports from either system
--
You received this message because you are subscribed to the Google Groups "Wazuh mailing list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to wazuh+unsubscribe@googlegroups.com.
To post to this group, send email to wa...@googlegroups.com.
Visit this group at https://groups.google.com/group/wazuh.
To view this discussion on the web visit https://groups.google.com/d/msgid/wazuh/384947d9-9b92-429c-9005-f5508a080ebb%40googlegroups.com.