Import LDAP Data Interchange Format File Via Ldifde.EXE

 Original Source: [Sigma source]
Title: Import LDAP Data Interchange Format File Via Ldifde.EXE
Status: test
Description:Detects the execution of "Ldifde.exe" with the import flag "-i". The can be abused to include HTTP-based arguments which will allow the arbitrary download of files from a remote server.
References:
  -https://twitter.com/0gtweet/status/1564968845726580736
  -https://strontic.github.io/xcyclopedia/library/ldifde.exe-979DE101F5059CEC1D2C56967CA2BAC0.html
  -https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731033(v=ws.11)
Author: @gott_cyber
Date: 2022-09-02
modified:2023-03-14
Tags:
  • -'attack.command-and-control'
  • -'attack.stealth'
  • -'attack.t1218'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\ldifde.exe' OriginalFileName:'ldifde.exe'   selection_cli:
    CommandLine|contains|all:
      -'-i'
      -'-f'

  condition:all of selection_*
Falsepositives:
  -Since the content of the files are unknown, false positives are expected
Level: medium