This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potentially Suspicious Child Process Of WinRAR.EXE
Original Source:
[Sigma source]
Title:
Potentially Suspicious Child Process Of WinRAR.EXE
Status:
test
Description:
Detects potentially suspicious child processes of WinRAR.exe.
References:
-https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
-https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831/blob/26ab6c40b6d2c09bb4fc60feaa4a3a90cfd20c23/Part-1-Overview.md
Author:
Nasreddine Bencherchali (Nextron Systems)
Date:
2023-08-31
modified:
None
Tags:
-'attack.execution'
-'attack.t1203'
Logsource:
category: process_creation
product: windows
Detection:
selection_parent:
ParentImage|endswith
:
'\WinRAR.exe'
selection_binaries:
- Image|endswith
:
- '\cmd.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\regsvr32.exe'
- '\rundll32.exe'
- '\wscript.exe'
- OriginalFileName
:
- 'Cmd.Exe'
- 'cscript.exe'
- 'mshta.exe'
- 'PowerShell.EXE'
- 'pwsh.dll'
- 'regsvr32.exe'
- 'RUNDLL32.EXE'
- 'wscript.exe'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
medium