This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Adplus.EXE Abuse
Original Source:
[Sigma source]
Title:
Potential Adplus.EXE Abuse
Status:
test
Description:
Detects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.
References:
-https://lolbas-project.github.io/lolbas/OtherMSBinaries/Adplus/
-https://twitter.com/nas_bench/status/1534916659676422152
-https://twitter.com/nas_bench/status/1534915321856917506
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2022-06-09
modified:
2023-06-23
Tags:
-'attack.execution'
-'attack.credential-access'
-'attack.t1003.001'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\adplus.exe'
OriginalFileName
:
'Adplus.exe'
selection_cli:
CommandLine|contains
:
-' -hang '
-' -pn '
-' -pmn '
-' -p '
-' -po '
-' -c '
-' -sc '
condition
:
all of selection_*
Falsepositives:
-Legitimate usage of Adplus for debugging purposes
Level:
high