Suspicious Process By Web Server Process

 Original Source: [Sigma source]
Title: Suspicious Process By Web Server Process
Status: test
Description:Detects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation
References:
  -https://media.defense.gov/2020/Jun/09/2002313081/-1/-1/0/CSI-DETECT-AND-PREVENT-WEB-SHELL-MALWARE-20200422.PDF
Author: Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems)
Date: 2019-01-16
modified:2024-11-26
Tags:
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.t1505.003'
  • -'attack.t1190'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_webserver_image:
    ParentImage|endswith:
      -'\caddy.exe'
      -'\httpd.exe'
      -'\nginx.exe'
      -'\php-cgi.exe'
      -'\php.exe'
      -'\tomcat.exe'
      -'\UMWorkerProcess.exe'
      -'\w3wp.exe'
      -'\ws_TomcatService.exe'

  selection_webserver_characteristics_tomcat1:
    ParentImage|endswith:
      -'\java.exe'
      -'\javaw.exe'

    ParentImage|contains:
      -'-tomcat-'
      -'\tomcat'

  selection_webserver_characteristics_tomcat2:
    ParentImage|endswith:
      -'\java.exe'
      -'\javaw.exe'

    ParentCommandLine|contains:
      -'CATALINA_HOME'
      -'catalina.home'
      -'catalina.jar'

  selection_anomaly_children:
    Image|endswith:
      -'\arp.exe'
      -'\at.exe'
      -'\bash.exe'
      -'\bitsadmin.exe'
      -'\certutil.exe'
      -'\cmd.exe'
      -'\cscript.exe'
      -'\dsget.exe'
      -'\hostname.exe'
      -'\nbtstat.exe'
      -'\net.exe'
      -'\net1.exe'
      -'\netdom.exe'
      -'\netsh.exe'
      -'\nltest.exe'
      -'\ntdsutil.exe'
      -'\powershell_ise.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\qprocess.exe'
      -'\query.exe'
      -'\qwinsta.exe'
      -'\reg.exe'
      -'\rundll32.exe'
      -'\sc.exe'
      -'\sh.exe'
      -'\wmic.exe'
      -'\wscript.exe'
      -'\wusa.exe'

  filter_main_fp_1:
    ParentImage|endswith: '\java.exe'
    CommandLine|endswith: 'Windows\system32\cmd.exe /c C:\ManageEngine\ADManager "Plus\ES\bin\elasticsearch.bat -Enode.name=RMP-NODE1 -pelasticsearch-pid.txt'
  filter_main_fp_2:
    ParentImage|endswith: '\java.exe'
    CommandLine|contains|all:
      -'sc query'
      -'ADManager Plus'

  condition:1 of selection_webserver_* and selection_anomaly_children and not 1 of filter_main_*
Falsepositives:
  -Particular web applications may spawn a shell process legitimately
Level: high