Kavremover Dropped Binary LOLBIN Usage

 Original Source: [Sigma source]
Title: Kavremover Dropped Binary LOLBIN Usage
Status: test
Description:Detects the execution of a signed binary dropped by Kaspersky Lab Products Remover (kavremover) which can be abused as a LOLBIN to execute arbitrary commands and binaries.
References:
  -https://nasbench.medium.com/lolbined-using-kaspersky-endpoint-security-kes-installer-to-execute-arbitrary-commands-1c999f1b7fea
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-11-01
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1127'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    CommandLine|contains: ' run run-cmd '
  filter_main_legit_parents:
    ParentImage|endswith:
      -'\cleanapi.exe'
      -'\kavremover.exe'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high