Suspicious Remote Child Process From Outlook

 Original Source: [Sigma source]
Title: Suspicious Remote Child Process From Outlook
Status: test
Description:Detects a suspicious child process spawning from Outlook where the image is located in a remote location (SMB/WebDav shares).
References:
  -https://github.com/sensepost/ruler
  -https://www.fireeye.com/blog/threat-research/2018/12/overruled-containing-a-potentially-destructive-adversary.html
  -https://speakerdeck.com/heirhabarov/hunting-for-persistence-via-microsoft-exchange-server-or-outlook?slide=49
Author: Markus Neis, Nasreddine Bencherchali (Nextron Systems)
Date: 2018-12-27
modified:2023-02-09
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\outlook.exe'
    Image|startswith: '\\\\'
  condition:selection
Falsepositives:
  -Unknown
Level: high