HackTool - LittleCorporal Generated Maldoc Injection

 Original Source: [Sigma source]
Title: HackTool - LittleCorporal Generated Maldoc Injection
Status: test
Description:Detects the process injection of a LittleCorporal generated Maldoc.
References:
  -https://github.com/connormcgarr/LittleCorporal
Author: Christian Burkard (Nextron Systems)
Date: 2021-08-09
modified:2023-11-28
Tags:
  • -'attack.execution'
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1204.002'
  • -'attack.t1055.003'
Logsource:
  • category: process_access
  • product: windows
Detection:
  selection:
    SourceImage|endswith: '\winword.exe'
    CallTrace|contains|all:
      -':\Windows\Microsoft.NET\Framework64\v2.'
      -'UNKNOWN'

  condition:selection
Falsepositives:
  -Unknown
Level: high