Suspicious Desktopimgdownldr Command

 Original Source: [Sigma source]
Title: Suspicious Desktopimgdownldr Command
Status: test
Description:Detects a suspicious Microsoft desktopimgdownldr execution with parameters used to download files from the Internet
References:
  -https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/
  -https://twitter.com/SBousseaden/status/1278977301745741825
Author: Florian Roth (Nextron Systems)
Date: 2020-07-03
modified:2021-11-27
Tags:
  • -'attack.command-and-control'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection1:
    CommandLine|contains: ' /lockscreenurl:'
  selection1_filter:
    CommandLine|contains:
      -'.jpg'
      -'.jpeg'
      -'.png'

  selection_reg:
    CommandLine|contains|all:
      -'reg delete'
      -'\PersonalizationCSP'

  condition:( selection1 and not selection1_filter ) or selection_reg
Falsepositives:
  -False positives depend on scripts and administrative tools used in the monitored environment
Level: high