Phishing Pattern ISO in Archive

 Original Source: [Sigma source]
Title: Phishing Pattern ISO in Archive
Status: test
Description:Detects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is a sign of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web)
References:
  -https://twitter.com/1ZRR4H/status/1534259727059787783
  -https://app.any.run/tasks/e1fe6a62-bce8-4323-a49a-63795d9afd5d/
Author: Florian Roth (Nextron Systems)
Date: 2022-06-07
modified:None
Tags:
  • -'attack.initial-access'
  • -'attack.t1566'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith:
      -'\Winrar.exe'
      -'\7zFM.exe'
      -'\peazip.exe'

    Image|endswith:
      -'\isoburn.exe'
      -'\PowerISO.exe'
      -'\ImgBurn.exe'

  condition:selection
Falsepositives:
  -Legitimate cases in which archives contain ISO or IMG files and the user opens the archive and the image via clicking and not extraction
Level: high