Suspicious Get-Variable.exe Creation

 Original Source: [Sigma source]
Title: Suspicious Get-Variable.exe Creation
Status: test
Description:Get-Variable is a valid PowerShell cmdlet WindowsApps is by default in the path where PowerShell is executed. So when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.
References:
  -https://blog.malwarebytes.com/threat-intelligence/2022/04/colibri-loader-combines-task-scheduler-and-powershell-in-clever-persistence-technique/
  -https://www.joesandbox.com/analysis/465533/0/html
Author: frack113
Date: 2022-04-23
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.stealth'
  • -'attack.t1546'
  • -'attack.t1027'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith: 'Local\Microsoft\WindowsApps\Get-Variable.exe'
  condition:selection
Falsepositives:
  -Unknown
Level: high