Esentutl Steals Browser Information

 Original Source: [Sigma source]
Title: Esentutl Steals Browser Information
Status: test
Description:One way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
References:
  -https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/
  -https://redcanary.com/threat-detection-report/threats/qbot/
  -https://thedfirreport.com/2022/10/31/follina-exploit-leads-to-domain-compromise/
Author: frack113
Date: 2022-02-13
modified:2024-03-05
Tags:
  • -'attack.collection'
  • -'attack.t1005'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\esentutl.exe' OriginalFileName:'esentutl.exe'   selection_flag:
    CommandLine|contains|windash: '-r'
  selection_webcache:
    CommandLine|contains: '\Windows\WebCache'
  condition:all of selection*
Falsepositives:
  -Legitimate use
Level: medium