Suspicious Process Created Via Wmic.EXE

 Original Source: [Sigma source]
Title: Suspicious Process Created Via Wmic.EXE
Status: test
Description:Detects WMIC executing "process call create" with suspicious calls to processes such as "rundll32", "regsrv32", etc.
References:
  -https://thedfirreport.com/2020/10/08/ryuks-return/
  -https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2020-10-12
modified:2023-02-14
Tags:
  • -'attack.execution'
  • -'attack.t1047'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'process '
      -'call '
      -'create '

    CommandLine|contains:
      -'rundll32'
      -'bitsadmin'
      -'regsvr32'
      -'cmd.exe /c '
      -'cmd.exe /k '
      -'cmd.exe /r '
      -'cmd /c '
      -'cmd /k '
      -'cmd /r '
      -'powershell'
      -'pwsh'
      -'certutil'
      -'cscript'
      -'wscript'
      -'mshta'
      -'\Users\Public\'
      -'\Windows\Temp\'
      -'\AppData\Local\'
      -'%temp%'
      -'%tmp%'
      -'%ProgramData%'
      -'%appdata%'
      -'%comspec%'
      -'%localappdata%'

  condition:selection
Falsepositives:
  -Unknown
Level: high