Suspicious Service Path Modification

 Original Source: [Sigma source]
Title: Suspicious Service Path Modification
Status: test
Description:Detects service path modification via the "sc" binary to a suspicious command or path
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md
  -https://web.archive.org/web/20180331144337/https://www.fireeye.com/blog/threat-research/2018/03/sanny-malware-delivery-method-updated-in-recently-observed-attacks.html
Author: Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems)
Date: 2019-10-21
modified:2022-11-18
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1543.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\sc.exe'
    CommandLine|contains|all:
      -'config'
      -'binPath'

    CommandLine|contains:
      -'powershell'
      -'cmd '
      -'mshta'
      -'wscript'
      -'cscript'
      -'rundll32'
      -'svchost'
      -'dllhost'
      -'cmd.exe /c'
      -'cmd.exe /k'
      -'cmd.exe /r'
      -'cmd /c'
      -'cmd /k'
      -'cmd /r'
      -'C:\Users\Public'
      -'\Downloads\'
      -'\Desktop\'
      -'\Microsoft\Windows\Start Menu\Programs\Startup\'
      -'C:\Windows\TEMP\'
      -'\AppData\Local\Temp'

  condition:selection
Falsepositives:
  -Unlikely
Level: high