This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious WebDav Client Execution Via Rundll32.EXE
Original Source:
[Sigma source]
Title:
Suspicious WebDav Client Execution Via Rundll32.EXE
Status:
test
Description:
Detects "svchost.exe" spawning "rundll32.exe" with command arguments like C:\windows\system32\davclnt.dll,DavSetCookie. This could be an indicator of exfiltration or use of WebDav to launch code (hosted on WebDav Server) or potentially a sign of exploitation of CVE-2023-23397
References:
-https://twitter.com/aceresponder/status/1636116096506818562
-https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/
-https://www.pwndefend.com/2023/03/15/the-long-game-persistent-hash-theft/
-https://www.microsoft.com/en-us/security/blog/wp-content/uploads/2023/03/Figure-7-sample-webdav-process-create-event.png
-https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/
Author:
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)
Date:
2023-03-16
modified:
2023-09-18
Tags:
-'attack.exfiltration'
-'attack.t1048.003'
-'cve.2023-23397'
Logsource:
category: process_creation
product: windows
Detection:
selection:
ParentImage|endswith
:
'\svchost.exe'
ParentCommandLine|contains
:
'-s WebClient'
Image|endswith
:
'\rundll32.exe'
CommandLine|contains
:
'C:\windows\system32\davclnt.dll,DavSetCookie'
CommandLine|re
:
'://\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}'
filter_local_ips:
CommandLine|contains
:
-'://10.'
-'://192.168.'
-'://172.16.'
-'://172.17.'
-'://172.18.'
-'://172.19.'
-'://172.20.'
-'://172.21.'
-'://172.22.'
-'://172.23.'
-'://172.24.'
-'://172.25.'
-'://172.26.'
-'://172.27.'
-'://172.28.'
-'://172.29.'
-'://172.30.'
-'://172.31.'
-'://127.'
-'://169.254.'
condition
:
selection and not 1 of filter_*
Falsepositives:
-Unknown
Level:
high