Uncommon Child Process Of Appvlp.EXE

 Original Source: [Sigma source]
Title: Uncommon Child Process Of Appvlp.EXE
Status: test
Description:Detects uncommon child processes of Appvlp.EXE Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands. Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder or to mark a file as a system file.
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/
Author: Sreeman
Date: 2020-03-13
modified:2023-11-09
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
  • -'attack.execution'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\appvlp.exe'
  filter_main_generic:
    Image|endswith:
      -':\Windows\SysWOW64\rundll32.exe'
      -':\Windows\System32\rundll32.exe'

  filter_optional_office_msoasb:
    Image|contains: ':\Program Files\Microsoft Office'
    Image|endswith: '\msoasb.exe'
  filter_optional_office_skype:
    Image|contains|all:
      -':\Program Files\Microsoft Office'
      -'\SkypeSrv\'

    Image|endswith: '\SKYPESERVER.EXE'
  filter_optional_office_msouc:
    Image|contains: ':\Program Files\Microsoft Office'
    Image|endswith: '\MSOUC.EXE'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium