This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
LOL-Binary Copied From System Directory
Original Source:
[Sigma source]
Title:
LOL-Binary Copied From System Directory
Status:
test
Description:
Detects a suspicious copy operation that tries to copy a known LOLBIN from system (System32, SysWOW64, WinSxS) directories to another on disk in order to bypass detections based on locations.
References:
-https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120
-https://web.archive.org/web/20180331144337/https://www.fireeye.com/blog/threat-research/2018/03/sanny-malware-delivery-method-updated-in-recently-observed-attacks.html
-https://thedfirreport.com/2023/08/28/html-smuggling-leads-to-domain-wide-ransomware/
-https://www.virustotal.com/gui/file/14e722855605ba78dc1d21153f0e1be90e7528149f2cd2d7d6eba8ef27534bdc/behavior
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2023-08-29
modified:
2025-11-27
Tags:
-'attack.stealth'
-'attack.t1036.003'
Logsource:
category: process_creation
product: windows
Detection:
selection_tools_cmd:
Image|endswith
:
'\cmd.exe'
CommandLine|contains
:
'copy '
selection_tools_pwsh:
Image|endswith
:
-'\powershell.exe'
-'\pwsh.exe'
CommandLine|contains
:
-'copy-item'
-' copy '
-'cpi '
-' cp '
selection_tools_other:
- Image|endswith
:
- '\robocopy.exe'
- '\xcopy.exe'
- OriginalFileName
:
- 'robocopy.exe'
- 'XCOPY.EXE'
selection_target_path:
CommandLine|contains
:
-'\System32'
-'\SysWOW64'
-'\WinSxS'
selection_target_lolbin:
CommandLine|contains
:
-'\bitsadmin.exe'
-'\calc.exe'
-'\certutil.exe'
-'\cmdl32.exe'
-'\cscript.exe'
-'\mshta.exe'
-'\rundll32.exe'
-'\wscript.exe'
-'\ie4uinit.exe'
condition
:
1 of selection_tools_* and all of selection_target_*
Falsepositives:
-Unknown
Level:
high