Bad Opsec Defaults Sacrificial Processes With Improper Arguments

 Original Source: [Sigma source]
Title: Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Status: test
Description:Detects attackers using tooling with bad opsec defaults. E.g. spawning a sacrificial process to inject a capability into the process without taking into account how the process is normally run. One trivial example of this is using rundll32.exe without arguments as a sacrificial process (default in CS, now highlighted by c2lint), running WerFault without arguments (Kraken - credit am0nsec), and other examples.
References:
  -https://blog.malwarebytes.com/malwarebytes-news/2020/10/kraken-attack-abuses-wer-service/
  -https://www.cobaltstrike.com/help-opsec
  -https://twitter.com/CyberRaiju/status/1251492025678983169
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/regsvr32
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/rundll32
  -https://learn.microsoft.com/en-us/dotnet/framework/tools/regasm-exe-assembly-registration-tool
  -https://learn.microsoft.com/en-us/dotnet/framework/tools/regsvcs-exe-net-services-installation-tool
Author: Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems)
Date: 2020-10-23
modified:2024-08-15
Tags:
  • -'attack.stealth'
  • -'attack.t1218.011'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_werfault:
    Image|endswith: '\WerFault.exe'
    CommandLine|endswith: 'WerFault.exe'
  selection_rundll32:
    Image|endswith: '\rundll32.exe'
    CommandLine|endswith: 'rundll32.exe'
  selection_regsvcs:
    Image|endswith: '\regsvcs.exe'
    CommandLine|endswith: 'regsvcs.exe'
  selection_regasm:
    Image|endswith: '\regasm.exe'
    CommandLine|endswith: 'regasm.exe'
  selection_regsvr32:
    Image|endswith: '\regsvr32.exe'
    CommandLine|endswith: 'regsvr32.exe'
  filter_optional_edge_update:
    ParentImage|contains: '\AppData\Local\Microsoft\EdgeUpdate\Install\{'
    Image|endswith: '\rundll32.exe'
    CommandLine|endswith: 'rundll32.exe'
  filter_optional_chromium_installer:
    ParentImage|contains:
      -'\AppData\Local\BraveSoftware\Brave-Browser\Application\'
      -'\AppData\Local\Google\Chrome\Application\'

    ParentImage|endswith: '\Installer\setup.exe'
    ParentCommandLine|contains: '--uninstall '
    Image|endswith: '\rundll32.exe'
    CommandLine|endswith: 'rundll32.exe'
  condition:1 of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Unlikely
Level: high