This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
Original Source:
[Sigma source]
Title:
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
Status:
test
Description:
Detects the use of iexpress.exe to create binaries via Self Extraction Directive (SED) files located in potentially suspicious locations. This behavior has been observed in-the-wild by different threat actors.
References:
-https://strontic.github.io/xcyclopedia/library/iexpress.exe-D594B2A33EFAFD0EABF09E3FDC05FCEA.html
-https://en.wikipedia.org/wiki/IExpress
-https://decoded.avast.io/janvojtesek/raspberry-robins-roshtyak-a-little-lesson-in-trickery/
-https://www.virustotal.com/gui/file/602f4ae507fa8de57ada079adff25a6c2a899bd25cd092d0af7e62cdb619c93c/behavior
Author:
Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems)
Date:
2024-02-05
modified:
2024-06-04
Tags:
-'attack.stealth'
-'attack.t1218'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\iexpress.exe'
OriginalFileName
:
'IEXPRESS.exe'
selection_cli:
CommandLine|contains|windash
:
' /n '
selection_paths:
CommandLine|contains
:
-':\ProgramData\'
-':\Temp\'
-':\Windows\System32\Tasks\'
-':\Windows\Tasks\'
-':\Windows\Temp\'
-'\AppData\Local\Temp\'
condition
:
all of selection_*
Falsepositives:
-Administrators building packages using iexpress.exe
Level:
high