HackTool - Jlaive In-Memory Assembly Execution

 Original Source: [Sigma source]
Title: HackTool - Jlaive In-Memory Assembly Execution
Status: test
Description:Detects the use of Jlaive to execute assemblies in a copied PowerShell
References:
  -https://jstnk9.github.io/jstnk9/research/Jlaive-Antivirus-Evasion-Tool
  -https://web.archive.org/web/20220514073704/https://github.com/ch2sh/Jlaive
Author: Jose Luis Sanchez Martinez (@Joseliyo_Jstnk)
Date: 2022-05-24
modified:2023-02-22
Tags:
  • -'attack.execution'
  • -'attack.t1059.003'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  parent_selection:
    ParentImage|endswith: '\cmd.exe'
    ParentCommandLine|endswith: '.bat'
  selection1:
    Image|endswith: '\xcopy.exe'
    CommandLine|contains|all:
      -'powershell.exe'
      -'.bat.exe'

  selection2:
    Image|endswith: '\xcopy.exe'
    CommandLine|contains|all:
      -'pwsh.exe'
      -'.bat.exe'

  selection3:
    Image|endswith: '\attrib.exe'
    CommandLine|contains|all:
      -'+s'
      -'+h'
      -'.bat.exe'

  condition:parent_selection and (1 of selection*)
Falsepositives:
  -Unknown
Level: medium