DLL Loaded From Suspicious Location Via Cmspt.EXE

 Original Source: [Sigma source]
Title: DLL Loaded From Suspicious Location Via Cmspt.EXE
Status: test
Description:Detects cmstp loading "dll" or "ocx" files from suspicious locations
References:
  -https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/TTPs/Defense%20Evasion/T1218%20-%20Signed%20Binary%20Proxy%20Execution/T1218.003%20-%20CMSTP/Procedures.yaml
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-08-30
modified:2023-02-17
Tags:
  • -'attack.stealth'
  • -'attack.t1218.003'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith: '\cmstp.exe'
    ImageLoaded|contains:
      -'\PerfLogs\'
      -'\ProgramData\'
      -'\Users\'
      -'\Windows\Temp\'
      -'C:\Temp\'

    ImageLoaded|endswith:
      -'.dll'
      -'.ocx'

  condition:selection
Falsepositives:
  -Unikely
Level: high