Suspicious Executable File Creation

 Original Source: [Sigma source]
Title: Suspicious Executable File Creation
Status: test
Description:Detect creation of suspicious executable file names. Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.
References:
  -https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service-path-c7a011a8d8ae
  -https://app.any.run/tasks/76c69e2d-01e8-49d9-9aea-fb7cc0c4d3ad/
Author: frack113
Date: 2022-09-05
modified:2023-12-11
Tags:
  • -'attack.stealth'
  • -'attack.t1564'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith:
      -':\$Recycle.Bin.exe'
      -':\Documents and Settings.exe'
      -':\MSOCache.exe'
      -':\PerfLogs.exe'
      -':\Recovery.exe'
      -'.bat.exe'
      -'.sys.exe'

  condition:selection
Falsepositives:
  -Unknown
Level: high