Potentially Suspicious Cabinet File Expansion

 Original Source: [Sigma source]
Title: Potentially Suspicious Cabinet File Expansion
Status: test
Description:Detects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks
References:
  -https://labs.sentinelone.com/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll
  -https://blog.malwarebytes.com/threat-intelligence/2021/08/new-variant-of-konni-malware-used-in-campaign-targetting-russia/
Author: Bhabesh Raj, X__Junior (Nextron Systems)
Date: 2021-07-30
modified:2024-11-13
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_cmd:
    Image|endswith: '\expand.exe'
    CommandLine|contains|windash: '-F:'
  selection_folders_1:
    CommandLine|contains:
      -':\Perflogs\'
      -':\ProgramData'
      -':\Users\Public\'
      -':\Windows\Temp\'
      -'\Admin$\'
      -'\AppData\Local\Temp\'
      -'\AppData\Roaming\'
      -'\C$\'
      -'\Temporary Internet'

  selection_folders_2:
    - CommandLine|contains|all:
      - ':\Users\'
      - '\Favorites\'
    - CommandLine|contains|all:
      - ':\Users\'
      - '\Favourites\'
    - CommandLine|contains|all:
      - ':\Users\'
      - '\Contacts\'
  filter_optional_dell:
    ParentImage: 'C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe'
    CommandLine|contains: 'C:\ProgramData\Dell\UpdateService\Temp\'
  condition:selection_cmd and 1 of selection_folders_* and not 1 of filter_optional_*
Falsepositives:
  -System administrator Usage
Level: medium