Potentially Suspicious Child Process Of WinRAR.EXE

 Original Source: [Sigma source]
Title: Potentially Suspicious Child Process Of WinRAR.EXE
Status: test
Description:Detects potentially suspicious child processes of WinRAR.exe.
References:
  -https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
  -https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831/blob/26ab6c40b6d2c09bb4fc60feaa4a3a90cfd20c23/Part-1-Overview.md
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-08-31
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1203'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith: '\WinRAR.exe'
  selection_binaries:
    - Image|endswith:
      - '\cmd.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\regsvr32.exe'
      - '\rundll32.exe'
      - '\wscript.exe'
    - OriginalFileName:
      - 'Cmd.Exe'
      - 'cscript.exe'
      - 'mshta.exe'
      - 'PowerShell.EXE'
      - 'pwsh.dll'
      - 'regsvr32.exe'
      - 'RUNDLL32.EXE'
      - 'wscript.exe'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium