Suspicious Serv-U Process Pattern

 Original Source: [Sigma source]
Title: Suspicious Serv-U Process Pattern
Status: test
Description:Detects a suspicious process pattern which could be a sign of an exploited Serv-U service
References:
  -https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/
Author: Florian Roth (Nextron Systems)
Date: 2021-07-14
modified:2022-07-14
Tags:
  • -'attack.credential-access'
  • -'attack.t1555'
  • -'cve.2021-35211'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\Serv-U.exe'
    Image|endswith:
      -'\cmd.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\wscript.exe'
      -'\cscript.exe'
      -'\sh.exe'
      -'\bash.exe'
      -'\schtasks.exe'
      -'\regsvr32.exe'
      -'\wmic.exe'
      -'\mshta.exe'
      -'\rundll32.exe'
      -'\msiexec.exe'
      -'\forfiles.exe'
      -'\scriptrunner.exe'

  condition:selection
Falsepositives:
  -Legitimate uses in which users or programs use the SSH service of Serv-U for remote command execution
Level: high