Title:
MMC Executing Files with Reversed Extensions Using RTLO Abuse
Status:
experimental
Description:Detects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.
References:
-https://www.unicode.org/versions/Unicode5.2.0/ch02.pdf
-https://en.wikipedia.org/wiki/Right-to-left_override
-https://tria.ge/241015-l98snsyeje/behavioral2
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-02-05
modified:None
Tags:
- -'attack.execution'
- -'attack.stealth'
- -'attack.t1204.002'
- -'attack.t1218.014'
- -'attack.t1036.002'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_image:
Image|endswith:
'\mmc.exe'
OriginalFileName:
'MMC.exe'
selection_commandline:
CommandLine|contains:
-'cod.msc'
-'fdp.msc'
-'ftr.msc'
-'lmth.msc'
-'slx.msc'
-'tdo.msc'
-'xcod.msc'
-'xslx.msc'
-'xtpp.msc'
condition:
all of selection_*
Falsepositives:
-Legitimate administrative actions using MMC to execute misnamed `.msc` files.
-Unconventional but non-malicious usage of RLO or reversed extensions.
Level:
high