Wmiprvse Wbemcomn DLL Hijack

 Original Source: [Sigma source]
Title: Wmiprvse Wbemcomn DLL Hijack
Status: test
Description:Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
References:
  -https://threathunterplaybook.com/hunts/windows/201009-RemoteWMIWbemcomnDLLHijack/notebook.html
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Date: 2020-10-12
modified:2022-10-09
Tags:
  • -'attack.execution'
  • -'attack.t1047'
  • -'attack.lateral-movement'
  • -'attack.t1021.002'
Logsource:
  • product: windows
  • category: image_load
Detection:
  selection:
    Image|endswith: '\wmiprvse.exe'
    ImageLoaded|endswith: '\wbem\wbemcomn.dll'
  condition:selection
Falsepositives:
  -Unknown
Level: high