Potential Adplus.EXE Abuse

 Original Source: [Sigma source]
Title: Potential Adplus.EXE Abuse
Status: test
Description:Detects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Adplus/
  -https://twitter.com/nas_bench/status/1534916659676422152
  -https://twitter.com/nas_bench/status/1534915321856917506
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-09
modified:2023-06-23
Tags:
  • -'attack.execution'
  • -'attack.credential-access'
  • -'attack.t1003.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\adplus.exe' OriginalFileName:'Adplus.exe'   selection_cli:
    CommandLine|contains:
      -' -hang '
      -' -pn '
      -' -pmn '
      -' -p '
      -' -po '
      -' -c '
      -' -sc '

  condition:all of selection_*
Falsepositives:
  -Legitimate usage of Adplus for debugging purposes
Level: high