This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious Get-Variable.exe Creation
Original Source:
[Sigma source]
Title:
Suspicious Get-Variable.exe Creation
Status:
test
Description:
Get-Variable is a valid PowerShell cmdlet WindowsApps is by default in the path where PowerShell is executed. So when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.
References:
-https://blog.malwarebytes.com/threat-intelligence/2022/04/colibri-loader-combines-task-scheduler-and-powershell-in-clever-persistence-technique/
-https://www.joesandbox.com/analysis/465533/0/html
Author:
frack113
Date:
2022-04-23
modified:
None
Tags:
-'attack.privilege-escalation'
-'attack.persistence'
-'attack.stealth'
-'attack.t1546'
-'attack.t1027'
Logsource:
product: windows
category: file_event
Detection:
selection:
TargetFilename|endswith
:
'Local\Microsoft\WindowsApps\Get-Variable.exe'
condition
:
selection
Falsepositives:
-Unknown
Level:
high