Potential Persistence Via Powershell Search Order Hijacking - Task

 Original Source: [Sigma source]
Title: Potential Persistence Via Powershell Search Order Hijacking - Task
Status: test
Description:Detects suspicious powershell execution via a schedule task where the command ends with an suspicious flags to hide the powershell instance instead of executeing scripts or commands. This could be a sign of persistence via PowerShell "Get-Variable" technique as seen being used in Colibri Loader
References:
  -https://blog.malwarebytes.com/threat-intelligence/2022/04/colibri-loader-combines-task-scheduler-and-powershell-in-clever-persistence-technique/
Author: pH-T (Nextron Systems), Florian Roth (Nextron Systems)
Date: 2022-04-08
modified:2023-02-03
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.t1053.005'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection:
    ParentImage: 'C:\WINDOWS\System32\svchost.exe'
    ParentCommandLine|contains|all:
      -'-k netsvcs'
      -'-s Schedule'

    CommandLine|endswith:
      -' -windowstyle hidden'
      -' -w hidden'
      -' -ep bypass'
      -' -noni'

  condition:selection
Falsepositives:
  -Unknown
Level: high