Legitimate Application Dropped Archive

 Original Source: [Sigma source]
Title: Legitimate Application Dropped Archive
Status: test
Description:Detects programs on a Windows system that should not write an archive to disk
References:
  -https://github.com/Neo23x0/sysmon-config/blob/3f808d9c022c507aae21a9346afba4a59dd533b9/sysmonconfig-export-block.xml#L1326
Author: frack113, Florian Roth
Date: 2022-08-21
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    Image|endswith:
      -'\winword.exe'
      -'\excel.exe'
      -'\powerpnt.exe'
      -'\msaccess.exe'
      -'\mspub.exe'
      -'\eqnedt32.exe'
      -'\visio.exe'
      -'\wordpad.exe'
      -'\wordview.exe'
      -'\certutil.exe'
      -'\certoc.exe'
      -'\CertReq.exe'
      -'\Desktopimgdownldr.exe'
      -'\esentutl.exe'
      -'\finger.exe'
      -'\notepad.exe'
      -'\AcroRd32.exe'
      -'\RdrCEF.exe'
      -'\mshta.exe'
      -'\hh.exe'

    TargetFilename|endswith:
      -'.zip'
      -'.rar'
      -'.7z'
      -'.diagcab'
      -'.appx'

  condition:selection
Falsepositives:
  -Unknown
Level: high