Suspicious Microsoft Office Child Process

 Original Source: [Sigma source]
Title: Suspicious Microsoft Office Child Process
Status: test
Description:Detects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
References:
  -https://www.hybrid-analysis.com/sample/465aabe132ccb949e75b8ab9c5bda36d80cf2fd503d52b8bad54e295f28bbc21?environmentId=100
  -https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html
  -https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
  -https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
  -https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
  -https://github.com/splunk/security_content/blob/300af51b88ad5d5b27ce4f5f54e4d6e6a3a2c06d/detections/endpoint/office_spawning_control.yml
  -https://twitter.com/andythevariable/status/1576953781581144064?s=20&t=QiJILvK4ZiBdR8RJe24u-A
  -https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
  -https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml
  -https://www.vmray.com/analyses/2d2fa29185ad/report/overview.html
  -https://app.any.run/tasks/c903e9c8-0350-440c-8688-3881b556b8e0/
Author: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io
Date: 2018-04-06
modified:2023-04-24
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1047'
  • -'attack.t1204.002'
  • -'attack.t1218.010'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_parent:
    ParentImage|endswith:
      -'\EQNEDT32.EXE'
      -'\EXCEL.EXE'
      -'\MSACCESS.EXE'
      -'\MSPUB.exe'
      -'\ONENOTE.EXE'
      -'\POWERPNT.exe'
      -'\VISIO.exe'
      -'\WINWORD.EXE'
      -'\wordpad.exe'
      -'\wordview.exe'

  selection_child_processes:
    - OriginalFileName:
      - 'bitsadmin.exe'
      - 'CertOC.exe'
      - 'CertUtil.exe'
      - 'Cmd.Exe'
      - 'CMSTP.EXE'
      - 'cscript.exe'
      - 'curl.exe'
      - 'HH.exe'
      - 'IEExec.exe'
      - 'InstallUtil.exe'
      - 'javaw.exe'
      - 'Microsoft.Workflow.Compiler.exe'
      - 'msdt.exe'
      - 'MSHTA.EXE'
      - 'msiexec.exe'
      - 'Msxsl.exe'
      - 'odbcconf.exe'
      - 'pcalua.exe'
      - 'PowerShell.EXE'
      - 'RegAsm.exe'
      - 'RegSvcs.exe'
      - 'REGSVR32.exe'
      - 'RUNDLL32.exe'
      - 'schtasks.exe'
      - 'ScriptRunner.exe'
      - 'wmic.exe'
      - 'WorkFolders.exe'
      - 'wscript.exe'
    - Image|endswith:
      - '\AppVLP.exe'
      - '\bash.exe'
      - '\bitsadmin.exe'
      - '\certoc.exe'
      - '\certutil.exe'
      - '\cmd.exe'
      - '\cmstp.exe'
      - '\control.exe'
      - '\cscript.exe'
      - '\curl.exe'
      - '\forfiles.exe'
      - '\hh.exe'
      - '\ieexec.exe'
      - '\installutil.exe'
      - '\javaw.exe'
      - '\mftrace.exe'
      - '\Microsoft.Workflow.Compiler.exe'
      - '\msbuild.exe'
      - '\msdt.exe'
      - '\mshta.exe'
      - '\msidb.exe'
      - '\msiexec.exe'
      - '\msxsl.exe'
      - '\odbcconf.exe'
      - '\pcalua.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\regasm.exe'
      - '\regsvcs.exe'
      - '\regsvr32.exe'
      - '\rundll32.exe'
      - '\schtasks.exe'
      - '\scrcons.exe'
      - '\scriptrunner.exe'
      - '\sh.exe'
      - '\svchost.exe'
      - '\verclsid.exe'
      - '\wmic.exe'
      - '\workfolders.exe'
      - '\wscript.exe'
  selection_child_susp_paths:
    Image|contains:
      -'\AppData\'
      -'\Users\Public\'
      -'\ProgramData\'
      -'\Windows\Tasks\'
      -'\Windows\Temp\'
      -'\Windows\System32\Tasks\'

  condition:selection_parent and 1 of selection_child_*
Falsepositives:
  -Unknown
Level: high