Suspicious File Execution From Internet Hosted WebDav Share

 Original Source: [Sigma source]
Title: Suspicious File Execution From Internet Hosted WebDav Share
Status: test
Description:Detects the execution of the "net use" command to mount a WebDAV server and then immediately execute some content in it. As seen being used in malicious LNK files
References:
  -https://twitter.com/ShadowChasing1/status/1552595370961944576
  -https://www.virustotal.com/gui/file/a63376ee1dba76361df73338928e528ca5b20171ea74c24581605366dcaa0104/behavior
Author: pH-T (Nextron Systems)
Date: 2022-09-01
modified:2023-02-21
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|contains:'\cmd.exe' OriginalFileName:'Cmd.EXE'   selection_base:
    CommandLine|contains|all:
      -' net use http'
      -'& start /b '
      -'\DavWWWRoot\'

  selection_ext:
    CommandLine|contains:
      -'.exe '
      -'.dll '
      -'.bat '
      -'.vbs '
      -'.ps1 '

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high