Scheduled Task Executing Encoded Payload from Registry

 Original Source: [Sigma source]
Title: Scheduled Task Executing Encoded Payload from Registry
Status: test
Description:Detects the creation of a schtask that potentially executes a base64 encoded payload stored in the Windows Registry using PowerShell.
References:
  -https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/
Author: pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-02-12
modified:2023-02-04
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.t1053.005'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\schtasks.exe' OriginalFileName:'schtasks.exe'   selection_cli_create:
    CommandLine|contains: '/Create'
  selection_cli_encoding:
    CommandLine|contains:
      -'FromBase64String'
      -'encodedcommand'

  selection_cli_get:
    CommandLine|contains:
      -'Get-ItemProperty'
      -' gp '

  selection_cli_hive:
    CommandLine|contains:
      -'HKCU:'
      -'HKLM:'
      -'registry::'
      -'HKEY_'

  condition:all of selection_*
Falsepositives:
  -Unlikely
Level: high