<<< Hide Navigation Hide TOC >>>
Suspicious Ping/Del Command Combination (54786ddc-5b8a-11ed-9b6a-0242ac120002)
Detects a method often used by ransomware. Which combines the "ping" to wait a couple of seconds and then "del" to delete the file in question. Its used to hide the file responsible for the initial infection for example
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Suspicious Ping/Del Command Combination (54786ddc-5b8a-11ed-9b6a-0242ac120002) | Sigma-Rules | File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) | Attack Pattern | 1 |
Indicator Removal - T1070 (799ace7f-e227-4411-baa0-8868704f2a69) | Attack Pattern | File Deletion - T1070.004 (d63a3fb8-9452-4e9d-a60a-54be68d5998c) | Attack Pattern | 2 |