Potential Arbitrary Command Execution Using Msdt.EXE

 Original Source: [Sigma source]
Title: Potential Arbitrary Command Execution Using Msdt.EXE
Status: test
Description:Detects processes leveraging the "ms-msdt" handler or the "msdt.exe" binary to execute arbitrary commands as seen in the follina (CVE-2022-30190) vulnerability
References:
  -https://twitter.com/nao_sec/status/1530196847679401984
  -https://app.any.run/tasks/713f05d2-fe78-4b9d-a744-f7c133e3fafb/
  -https://twitter.com/_JohnHammond/status/1531672601067675648
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-05-29
modified:2024-03-13
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\msdt.exe' OriginalFileName:'msdt.exe'   selection_cmd_inline:
    CommandLine|contains: 'IT_BrowseForFile='
  selection_cmd_answerfile_flag:
    CommandLine|contains: ' PCWDiagnostic'
  selection_cmd_answerfile_param:
    CommandLine|contains|windash: ' -af '
  condition:selection_img and (selection_cmd_inline or all of selection_cmd_answerfile_*)
Falsepositives:
  -Unknown
Level: high