Renamed Office Binary Execution

 Original Source: [Sigma source]
Title: Renamed Office Binary Execution
Status: test
Description:Detects the execution of a renamed office binary
References:
  -https://infosec.exchange/@sbousseaden/109542254124022664
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-20
modified:2025-12-09
Tags:
  • -'attack.stealth'
  • -'attack.t1036.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    - OriginalFileName:
      - 'Excel.exe'
      - 'MSACCESS.EXE'
      - 'MSPUB.EXE'
      - 'OneNote.exe'
      - 'OneNoteM.exe'
      - 'OUTLOOK.EXE'
      - 'POWERPNT.EXE'
      - 'WinWord.exe'
      - 'Olk.exe'
    - Description:
      - 'Microsoft Access'
      - 'Microsoft Excel'
      - 'Microsoft OneNote'
      - 'Microsoft Outlook'
      - 'Microsoft PowerPoint'
      - 'Microsoft Publisher'
      - 'Microsoft Word'
      - 'Sent to OneNote Tool'
  filter_main_legit_names:
    Image|endswith:
      -'\EXCEL.exe'
      -'\excelcnv.exe'
      -'\MSACCESS.exe'
      -'\MSPUB.EXE'
      -'\ONENOTE.EXE'
      -'\ONENOTEM.EXE'
      -'\OUTLOOK.EXE'
      -'\POWERPNT.EXE'
      -'\WINWORD.exe'
      -'\OLK.EXE'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high