Suspicious Outlook Child Process

 Original Source: [Sigma source]
Title: Suspicious Outlook Child Process
Status: test
Description:Detects a suspicious process spawning from an Outlook process.
References:
  -https://www.hybrid-analysis.com/sample/465aabe132ccb949e75b8ab9c5bda36d80cf2fd503d52b8bad54e295f28bbc21?environmentId=100
  -https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html
Author: Michael Haag, Florian Roth (Nextron Systems), Markus Neis, Elastic, FPT.EagleEye Team
Date: 2022-02-28
modified:2023-02-04
Tags:
  • -'attack.execution'
  • -'attack.t1204.002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\OUTLOOK.EXE'
    Image|endswith:
      -'\AppVLP.exe'
      -'\bash.exe'
      -'\cmd.exe'
      -'\cscript.exe'
      -'\forfiles.exe'
      -'\hh.exe'
      -'\mftrace.exe'
      -'\msbuild.exe'
      -'\msdt.exe'
      -'\mshta.exe'
      -'\msiexec.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\regsvr32.exe'
      -'\schtasks.exe'
      -'\scrcons.exe'
      -'\scriptrunner.exe'
      -'\sh.exe'
      -'\svchost.exe'
      -'\wmic.exe'
      -'\wscript.exe'

  condition:selection
Falsepositives:
  -Unknown
Level: high