Potential Process Injection Via Msra.EXE

 Original Source: [Sigma source]
Title: Potential Process Injection Via Msra.EXE
Status: test
Description:Detects potential process injection via Microsoft Remote Asssistance (Msra.exe) by looking at suspicious child processes spawned from the aforementioned process. It has been a target used by many threat actors and used for discovery and persistence tactics
References:
  -https://www.microsoft.com/security/blog/2021/12/09/a-closer-look-at-qakbots-latest-building-blocks-and-how-to-knock-them-down/
  -https://www.fortinet.com/content/dam/fortinet/assets/analyst-reports/ar-qakbot.pdf
Author: Alexander McDonald
Date: 2022-06-24
modified:2023-02-03
Tags:
  • -'attack.privilege-escalation'
  • -'attack.stealth'
  • -'attack.t1055'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\msra.exe'
    ParentCommandLine|endswith: 'msra.exe'
    Image|endswith:
      -'\arp.exe'
      -'\cmd.exe'
      -'\net.exe'
      -'\netstat.exe'
      -'\nslookup.exe'
      -'\route.exe'
      -'\schtasks.exe'
      -'\whoami.exe'

  condition:selection
Falsepositives:
  -Legitimate use of Msra.exe
Level: high