Microsoft Excel Add-In Loaded From Uncommon Location

 Original Source: [Sigma source]
Title: Microsoft Excel Add-In Loaded From Uncommon Location
Status: test
Description:Detects Microsoft Excel loading an Add-In (.xll) file from an uncommon location
References:
  -https://www.mandiant.com/resources/blog/lnk-between-browsers
  -https://wazuh.com/blog/detecting-xll-files-used-for-dropping-fin7-jssloader-with-wazuh/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-05-12
modified:None
Tags:
  • -'attack.execution'
  • -'attack.t1204.002'
Logsource:
  • category: image_load
  • product: windows
Detection:
  selection:
    Image|endswith: '\excel.exe'
    ImageLoaded|contains:
      -'\Desktop\'
      -'\Downloads\'
      -'\Perflogs\'
      -'\Temp\'
      -'\Users\Public\'
      -'\Windows\Tasks\'

    ImageLoaded|endswith: '.xll'
  condition:selection
Falsepositives:
  -Some tuning might be required to allow or remove certain locations used by the rule if you consider them as safe locations
Level: medium