Webshell Hacking Activity Patterns

 Original Source: [Sigma source]
Title: Webshell Hacking Activity Patterns
Status: test
Description:Detects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system
References:
  -https://youtu.be/7aemGhaE9ds?t=641
Author: Florian Roth (Nextron Systems)
Date: 2022-03-17
modified:2023-11-09
Tags:
  • -'attack.persistence'
  • -'attack.discovery'
  • -'attack.t1505.003'
  • -'attack.t1018'
  • -'attack.t1033'
  • -'attack.t1087'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_webserver_image:
    ParentImage|endswith:
      -'\caddy.exe'
      -'\httpd.exe'
      -'\nginx.exe'
      -'\php-cgi.exe'
      -'\w3wp.exe'
      -'\ws_tomcatservice.exe'

  selection_webserver_characteristics_tomcat1:
    ParentImage|endswith:
      -'\java.exe'
      -'\javaw.exe'

    ParentImage|contains:
      -'-tomcat-'
      -'\tomcat'

  selection_webserver_characteristics_tomcat2:
    ParentImage|endswith:
      -'\java.exe'
      -'\javaw.exe'

    CommandLine|contains:
      -'catalina.jar'
      -'CATALINA_HOME'

  selection_child_1:
    CommandLine|contains|all:
      -'rundll32'
      -'comsvcs'

  selection_child_2:
    CommandLine|contains|all:
      -' -hp'
      -' a '
      -' -m'

  selection_child_3:
    CommandLine|contains|all:
      -'net'
      -' user '
      -' /add'

  selection_child_4:
    CommandLine|contains|all:
      -'net'
      -' localgroup '
      -' administrators '
      -'/add'

  selection_child_5:
    Image|endswith:
      -'\ntdsutil.exe'
      -'\ldifde.exe'
      -'\adfind.exe'
      -'\procdump.exe'
      -'\Nanodump.exe'
      -'\vssadmin.exe'
      -'\fsutil.exe'

  selection_child_6:
    CommandLine|contains:
      -' -decode '
      -' -NoP '
      -' -W Hidden '
      -' /decode '
      -' /ticket:'
      -' sekurlsa'
      -'.dmp full'
      -'.downloadfile('
      -'.downloadstring('
      -'FromBase64String'
      -'process call create'
      -'reg save '
      -'whoami /priv'

  condition:1 of selection_webserver_* and 1 of selection_child_*
Falsepositives:
  -Unlikely
Level: high