Windows Shell/Scripting Processes Spawning Suspicious Programs

 Original Source: [Sigma source]
Title: Windows Shell/Scripting Processes Spawning Suspicious Programs
Status: test
Description:Detects suspicious child processes of a Windows shell and scripting processes such as wscript, rundll32, powershell, mshta...etc.
References:
  -https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html
Author: Florian Roth (Nextron Systems), Tim Shelton
Date: 2018-04-06
modified:2023-05-23
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059.005'
  • -'attack.t1059.001'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith:
      -'\mshta.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\rundll32.exe'
      -'\cscript.exe'
      -'\wscript.exe'
      -'\wmiprvse.exe'
      -'\regsvr32.exe'

    Image|endswith:
      -'\schtasks.exe'
      -'\nslookup.exe'
      -'\certutil.exe'
      -'\bitsadmin.exe'
      -'\mshta.exe'

  filter_ccmcache:
    CurrentDirectory|contains: '\ccmcache\'
  filter_amazon:
    ParentCommandLine|contains:
      -'\Program Files\Amazon\WorkSpacesConfig\Scripts\setup-scheduledtask.ps1'
      -'\Program Files\Amazon\WorkSpacesConfig\Scripts\set-selfhealing.ps1'
      -'\Program Files\Amazon\WorkSpacesConfig\Scripts\check-workspacehealth.ps1'
      -'\nessus_'

  filter_nessus:
    CommandLine|contains: '\nessus_'
  filter_sccm_install:
    ParentImage|endswith: '\mshta.exe'
    Image|endswith: '\mshta.exe'
    ParentCommandLine|contains|all:
      -'C:\MEM_Configmgr_'
      -'\splash.hta'
      -'{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}'

    CommandLine|contains|all:
      -'C:\MEM_Configmgr_'
      -'\SMSSETUP\BIN\'
      -'\autorun.hta'
      -'{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}'

  condition:selection and not 1 of filter_*
Falsepositives:
  -Administrative scripts
  -Microsoft SCCM
Level: high