Potential Defense Evasion Via Rename Of Highly Relevant Binaries

 Original Source: [Sigma source]
Title: Potential Defense Evasion Via Rename Of Highly Relevant Binaries
Status: test
Description:Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
References:
  -https://mgreen27.github.io/posts/2019/05/12/BinaryRename.html
  -https://mgreen27.github.io/posts/2019/05/29/BinaryRename2.html
  -https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/megacortex-ransomware-spotted-attacking-enterprise-networks
  -https://twitter.com/christophetd/status/1164506034720952320
  -https://threatresearch.ext.hp.com/svcready-a-new-loader-reveals-itself/
  -https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke
Author: Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113
Date: 2019-06-15
modified:2026-06-29
Tags:
  • -'attack.stealth'
  • -'attack.t1036.003'
  • -'car.2013-05-009'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Description:'Execute processes remotely' Product:'Sysinternals PsExec'     - Description|startswith:
      - 'Windows PowerShell'
      - 'pwsh'
    - OriginalFileName:
      - 'certutil.exe'
      - 'cmstp.exe'
      - 'cscript.exe'
      - 'IE4UINIT.EXE'
      - 'finger.exe'
      - 'mshta.exe'
      - 'msiexec.exe'
      - 'msxsl.exe'
      - 'powershell_ise.exe'
      - 'powershell.exe'
      - 'psexec.c'
      - 'psexec.exe'
      - 'psexesvc.exe'
      - 'pwsh.dll'
      - 'reg.exe'
      - 'regsvr32.exe'
      - 'rundll32.exe'
      - 'WerMgr'
      - 'wmic.exe'
      - 'wscript.exe'
  filter:
    Image|endswith:
      -'\certutil.exe'
      -'\cmstp.exe'
      -'\cscript.exe'
      -'\ie4uinit.exe'
      -'\finger.exe'
      -'\mshta.exe'
      -'\msiexec.exe'
      -'\msxsl.exe'
      -'\powershell_ise.exe'
      -'\powershell.exe'
      -'\psexec.exe'
      -'\psexec64.exe'
      -'\psexec64a.exe'
      -'\PSEXESVC.exe'
      -'\pwsh.exe'
      -'\reg.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\wermgr.exe'
      -'\wmic.exe'
      -'\wscript.exe'

  condition:selection and not filter
Falsepositives:
  -Custom applications use renamed binaries adding slight change to binary name. Typically this is easy to spot and add to whitelist
  -PsExec installed via Windows Store doesn't contain original filename field (False negative)
Level: high