HackTool - Koadic Execution

 Original Source: [Sigma source]
Title: HackTool - Koadic Execution
Status: test
Description:Detects command line parameters used by Koadic hack tool
References:
  -https://unit42.paloaltonetworks.com/unit42-sofacy-groups-parallel-attacks/
  -https://github.com/offsecginger/koadic/blob/457f9a3ff394c989cdb4c599ab90eb34fb2c762c/data/stager/js/stdlib.js
  -https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/
Author: wagga, Jonhnathan Ribeiro, oscd.community
Date: 2020-01-12
modified:2023-02-11
Tags:
  • -'attack.execution'
  • -'attack.t1059.003'
  • -'attack.t1059.005'
  • -'attack.t1059.007'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\cmd.exe' OriginalFileName:'Cmd.Exe'   selection_cli:
    CommandLine|contains|all:
      -'/q'
      -'/c'
      -'chcp'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high