Potential Defense Evasion Via Binary Rename

 Original Source: [Sigma source]
Title: Potential Defense Evasion Via Binary Rename
Status: test
Description:Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
References:
  -https://mgreen27.github.io/posts/2019/05/12/BinaryRename.html
  -https://mgreen27.github.io/posts/2019/05/29/BinaryRename2.html
  -https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1036.003/T1036.003.md#atomic-test-1---masquerading-as-windows-lsass-process
  -https://www.splunk.com/en_us/blog/security/inno-setup-malware-redline-stealer-campaign.html
Author: Matthew Green @mgreen27, Ecco, James Pemberton @4A616D6573, oscd.community, Andreas Hunkeler (@Karneades)
Date: 2019-06-15
modified:2026-06-05
Tags:
  • -'attack.stealth'
  • -'attack.t1036.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    OriginalFileName:
      -'Cmd.Exe'
      -'CONHOST.EXE'
      -'7z.exe'
      -'7za.exe'
      -'7zr.exe'
      -'WinRAR.exe'
      -'wevtutil.exe'
      -'net.exe'
      -'net1.exe'
      -'netsh.exe'
      -'InstallUtil.exe'

  filter:
    Image|endswith:
      -'\cmd.exe'
      -'\conhost.exe'
      -'\7z.exe'
      -'\7za.exe'
      -'\7zr.exe'
      -'\WinRAR.exe'
      -'\wevtutil.exe'
      -'\net.exe'
      -'\net1.exe'
      -'\netsh.exe'
      -'\InstallUtil.exe'

  condition:selection and not filter
Falsepositives:
  -Custom applications use renamed binaries adding slight change to binary name. Typically this is easy to spot and add to whitelist
Level: medium