Title:
Potential Persistence Via Microsoft Office Startup Folder
Status:
test
Description:Detects creation of Microsoft Office files inside of one of the default startup folders in order to achieve persistence.
References:
-https://insight-jp.nttsecurity.com/post/102hojk/operation-restylink-apt-campaign-targeting-japanese-companies
-https://learn.microsoft.com/en-us/office/troubleshoot/excel/use-startup-folders
Author: Max Altgelt (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-02
modified:2023-06-22
Tags:
- -'attack.persistence'
- -'attack.t1137'
Logsource:
- category: file_event
- product: windows
Detection:
selection_word_paths:
TargetFilename|contains:
'\Microsoft\Word\STARTUP'
- TargetFilename|contains|all:
- '\Office'
- '\Program Files'
- '\STARTUP'
selection_word_extension:
TargetFilename|endswith:
-'.doc'
-'.docm'
-'.docx'
-'.dot'
-'.dotm'
-'.rtf'
selection_excel_paths:
TargetFilename|contains:
'\Microsoft\Excel\XLSTART'
- TargetFilename|contains|all:
- '\Office'
- '\Program Files'
- '\XLSTART'
selection_excel_extension:
TargetFilename|endswith:
-'.xls'
-'.xlsm'
-'.xlsx'
-'.xlt'
-'.xltm'
filter_main_office:
Image|endswith:
-'\WINWORD.exe'
-'\EXCEL.exe'
condition:
(all of selection_word_* or all of selection_excel_*) and not filter_main_office
Falsepositives:
-Loading a user environment from a backup or a domain controller
-Synchronization of templates
Level:
high