Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location

 Original Source: [Sigma source]
Title: Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
Status: test
Description:Detects the use of iexpress.exe to create binaries via Self Extraction Directive (SED) files located in potentially suspicious locations. This behavior has been observed in-the-wild by different threat actors.
References:
  -https://strontic.github.io/xcyclopedia/library/iexpress.exe-D594B2A33EFAFD0EABF09E3FDC05FCEA.html
  -https://en.wikipedia.org/wiki/IExpress
  -https://decoded.avast.io/janvojtesek/raspberry-robins-roshtyak-a-little-lesson-in-trickery/
  -https://www.virustotal.com/gui/file/602f4ae507fa8de57ada079adff25a6c2a899bd25cd092d0af7e62cdb619c93c/behavior
Author: Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems)
Date: 2024-02-05
modified:2024-06-04
Tags:
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\iexpress.exe' OriginalFileName:'IEXPRESS.exe'   selection_cli:
    CommandLine|contains|windash: ' /n '
  selection_paths:
    CommandLine|contains:
      -':\ProgramData\'
      -':\Temp\'
      -':\Windows\System32\Tasks\'
      -':\Windows\Tasks\'
      -':\Windows\Temp\'
      -'\AppData\Local\Temp\'

  condition:all of selection_*
Falsepositives:
  -Administrators building packages using iexpress.exe
Level: high