Suspicious Screensaver Binary File Creation

 Original Source: [Sigma source]
Title: Suspicious Screensaver Binary File Creation
Status: test
Description:Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.002/T1546.002.md
Author: frack113
Date: 2021-12-29
modified:2022-11-08
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.002'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith: '.scr'
  filter_generic:
    Image|endswith:
      -'\Kindle.exe'
      -'\Bin\ccSvcHst.exe'

  filter_tiworker:
    Image|endswith: '\TiWorker.exe'
    TargetFilename|endswith: '\uwfservicingscr.scr'
  condition:selection and not 1 of filter_*
Falsepositives:
  -Unknown
Level: medium