DLL Execution via Rasautou.exe

 Original Source: [Sigma source]
Title: DLL Execution via Rasautou.exe
Status: test
Description:Detects using Rasautou.exe for loading arbitrary .DLL specified in -d option and executes the export specified in -p.
References:
  -https://lolbas-project.github.io/lolbas/Binaries/Rasautou/
  -https://github.com/fireeye/DueDLLigence
  -https://www.fireeye.com/blog/threat-research/2019/10/staying-hidden-on-the-endpoint-evading-detection-with-shellcode.html
Author: Julia Fomina, oscd.community
Date: 2020-10-09
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • product: windows
  • category: process_creation
  • definition: Since options '-d' and '-p' were removed in Windows 10 this rule is relevant only for Windows before 10. And as Windows 7 doesn't log command line in 4688 by default, to detect this attack you need Sysmon 1 configured or KB3004375 installed for command-line auditing (https://support.microsoft.com/en-au/help/3004375/microsoft-security-advisory-update-to-improve-windows-command-line-aud)
Detection:
  selection_img:
Image|endswith:'\rasautou.exe' OriginalFileName:'rasdlui.exe'   selection_cli:
    CommandLine|contains|all:
      -' -d '
      -' -p '

  condition:all of selection*
Falsepositives:
  -Unlikely
Level: medium