Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE

 Original Source: [Sigma source]
Title: Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE
Status: test
Description:Detects Netsh command execution that whitelists a program located in a suspicious location in the Windows Firewall
References:
  -https://www.virusradar.com/en/Win32_Kasidet.AD/description
  -https://www.hybrid-analysis.com/sample/07e789f4f2f3259e7559fdccb36e96814c2dbff872a21e1fa03de9ee377d581f?environmentId=100
Author: Sander Wiebing, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community
Date: 2020-05-25
modified:2023-12-11
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1686.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\netsh.exe' OriginalFileName:'netsh.exe'   selection_cli:
    - CommandLine|contains|all:
      - 'firewall'
      - 'add'
      - 'allowedprogram'
    - CommandLine|contains|all:
      - 'advfirewall'
      - 'firewall'
      - 'add'
      - 'rule'
      - 'action=allow'
      - 'program='
  selection_paths:
    CommandLine|contains:
      -':\$Recycle.bin\'
      -':\RECYCLER.BIN\'
      -':\RECYCLERS.BIN\'
      -':\SystemVolumeInformation\'
      -':\Temp\'
      -':\Users\Default\'
      -':\Users\Desktop\'
      -':\Users\Public\'
      -':\Windows\addins\'
      -':\Windows\cursors\'
      -':\Windows\debug\'
      -':\Windows\drivers\'
      -':\Windows\fonts\'
      -':\Windows\help\'
      -':\Windows\system32\tasks\'
      -':\Windows\Tasks\'
      -':\Windows\Temp\'
      -'\Downloads\'
      -'\Local Settings\Temporary Internet Files\'
      -'\Temporary Internet Files\Content.Outlook\'
      -'%Public%\'
      -'%TEMP%'
      -'%TMP%'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high