Potential Arbitrary File Download Using Office Application

 Original Source: [Sigma source]
Title: Potential Arbitrary File Download Using Office Application
Status: test
Description:Detects potential arbitrary file download using a Microsoft Office application
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/
  -https://lolbas-project.github.io/lolbas/Binaries/Msoxmled/
  -https://medium.com/@reegun/unsanitized-file-validation-leads-to-malicious-payload-download-via-office-binaries-202d02db7191
Author: Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community
Date: 2022-05-17
modified:2026-09-25
Tags:
  • -'attack.stealth'
  • -'attack.t1202'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\EXCEL.EXE'
      - '\MSOXMLED.EXE'
      - '\POWERPNT.EXE'
      - '\WINWORD.exe'
    - OriginalFileName:
      - 'Excel.exe'
      - 'msoxmled.exe'
      - 'POWERPNT.EXE'
      - 'WinWord.exe'
  selection_http:
    CommandLine|contains:
      -'http://'
      -'https://'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high