This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Microsoft Office Child Process
Original Source:
[Sigma source]
Title:
Suspicious Microsoft Office Child Process
Status:
test
Description:
Detects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
References:
-https://www.hybrid-analysis.com/sample/465aabe132ccb949e75b8ab9c5bda36d80cf2fd503d52b8bad54e295f28bbc21?environmentId=100
-https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html
-https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
-https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
-https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
-https://github.com/splunk/security_content/blob/300af51b88ad5d5b27ce4f5f54e4d6e6a3a2c06d/detections/endpoint/office_spawning_control.yml
-https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
-https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
-https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml
-https://www.vmray.com/analyses/2d2fa29185ad/report/overview.html
-https://app.any.run/tasks/c903e9c8-0350-440c-8688-3881b556b8e0/
Author:
Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io
Date:
2018-04-06
modified:
2023-04-24
Tags:
-'attack.execution'
-'attack.stealth'
-'attack.t1047'
-'attack.t1204.002'
-'attack.t1218.010'
Logsource:
category: process_creation
product: windows
Detection:
selection_parent:
ParentImage|endswith
:
-'\EQNEDT32.EXE'
-'\EXCEL.EXE'
-'\MSACCESS.EXE'
-'\MSPUB.exe'
-'\ONENOTE.EXE'
-'\POWERPNT.exe'
-'\VISIO.exe'
-'\WINWORD.EXE'
-'\wordpad.exe'
-'\wordview.exe'
selection_child_processes:
- OriginalFileName
:
- 'bitsadmin.exe'
- 'CertOC.exe'
- 'CertUtil.exe'
- 'Cmd.Exe'
- 'CMSTP.EXE'
- 'cscript.exe'
- 'curl.exe'
- 'HH.exe'
- 'IEExec.exe'
- 'InstallUtil.exe'
- 'javaw.exe'
- 'Microsoft.Workflow.Compiler.exe'
- 'msdt.exe'
- 'MSHTA.EXE'
- 'msiexec.exe'
- 'Msxsl.exe'
- 'odbcconf.exe'
- 'pcalua.exe'
- 'PowerShell.EXE'
- 'RegAsm.exe'
- 'RegSvcs.exe'
- 'REGSVR32.exe'
- 'RUNDLL32.exe'
- 'schtasks.exe'
- 'ScriptRunner.exe'
- 'wmic.exe'
- 'WorkFolders.exe'
- 'wscript.exe'
- Image|endswith
:
- '\AppVLP.exe'
- '\bash.exe'
- '\bitsadmin.exe'
- '\certoc.exe'
- '\certutil.exe'
- '\cmd.exe'
- '\cmstp.exe'
- '\control.exe'
- '\cscript.exe'
- '\curl.exe'
- '\forfiles.exe'
- '\hh.exe'
- '\ieexec.exe'
- '\installutil.exe'
- '\javaw.exe'
- '\mftrace.exe'
- '\Microsoft.Workflow.Compiler.exe'
- '\msbuild.exe'
- '\msdt.exe'
- '\mshta.exe'
- '\msidb.exe'
- '\msiexec.exe'
- '\msxsl.exe'
- '\odbcconf.exe'
- '\pcalua.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\regasm.exe'
- '\regsvcs.exe'
- '\regsvr32.exe'
- '\rundll32.exe'
- '\schtasks.exe'
- '\scrcons.exe'
- '\scriptrunner.exe'
- '\sh.exe'
- '\svchost.exe'
- '\verclsid.exe'
- '\wmic.exe'
- '\workfolders.exe'
- '\wscript.exe'
selection_child_susp_paths:
Image|contains
:
-'\AppData\'
-'\Users\Public\'
-'\ProgramData\'
-'\Windows\Tasks\'
-'\Windows\Temp\'
-'\Windows\System32\Tasks\'
condition
:
selection_parent and 1 of selection_child_*
Falsepositives:
-Unknown
Level:
high