Legitimate Application Dropped Executable

 Original Source: [Sigma source]
Title: Legitimate Application Dropped Executable
Status: test
Description:Detects LOLBINs and applications that should not legitimately drop executable or executable-equivalent files to disk. This may indicate malware staging, process injection, or abuse of a trusted binary for payload delivery.
References:
  -https://github.com/Neo23x0/sysmon-config/blob/3f808d9c022c507aae21a9346afba4a59dd533b9/sysmonconfig-export-block.xml#L1326
  -https://dmpdump.github.io/posts/TelegramRat/
  -https://www.virustotal.com/gui/file/a0d5b30578acd1df9139e7a8a4bfc659dc2cf48f4dc0c5804b70890adeb9fa21/behavior
Author: frack113, Florian Roth (Nextron Systems)
Date: 2022-08-21
modified:2026-05-11
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith:
      -'\eqnedt32.exe'
      -'\wordpad.exe'
      -'\wordview.exe'
      -'\certutil.exe'
      -'\certoc.exe'
      -'\CertReq.exe'
      -'\Desktopimgdownldr.exe'
      -'\esentutl.exe'
      -'\mshta.exe'
      -'\AcroRd32.exe'
      -'\RdrCEF.exe'
      -'\hh.exe'
      -'\finger.exe'

    TargetFilename|endswith:
      -'.com'
      -'.dll'
      -'.exe'
      -'.jar'
      -'.ocx'
      -'.pyc'

  condition:selection
Falsepositives:
  -Unknown
Level: high