Suspicious Binary In User Directory Spawned From Office Application

 Original Source: [Sigma source]
Title: Suspicious Binary In User Directory Spawned From Office Application
Status: test
Description:Detects an executable in the users directory started from one of the Microsoft Office suite applications (Word, Excel, PowerPoint, Publisher, Visio)
References:
  -https://blog.morphisec.com/fin7-not-finished-morphisec-spots-new-campaign
  -https://www.virustotal.com/gui/file/23160972c6ae07f740800fa28e421a81d7c0ca5d5cab95bc082b4a986fbac57
Author: Jason Lynch
Date: 2019-04-02
modified:2023-02-04
Tags:
  • -'attack.execution'
  • -'attack.t1204.002'
  • -'attack.g0046'
  • -'car.2013-05-002'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith:
      -'\WINWORD.EXE'
      -'\EXCEL.EXE'
      -'\POWERPNT.exe'
      -'\MSPUB.exe'
      -'\VISIO.exe'
      -'\MSACCESS.exe'
      -'\EQNEDT32.exe'

    Image|startswith: 'C:\users\'
    Image|endswith: '.exe'
  filter:
    Image|endswith: '\Teams.exe'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high