Writing Of Malicious Files To The Fonts Folder

 Original Source: [Sigma source]
Title: Writing Of Malicious Files To The Fonts Folder
Status: test
Description:Monitors for the hiding possible malicious files in the C:\Windows\Fonts\ location. This folder doesn't require admin privillege to be written and executed from.
References:
  -https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
Author: Sreeman
Date: 2020-04-21
modified:2022-03-08
Tags:
  • -'attack.stealth'
  • -'attack.t1211'
  • -'attack.t1059'
  • -'attack.persistence'
  • -'attack.execution'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_1:
    CommandLine|contains:
      -'echo'
      -'copy'
      -'type'
      -'file createnew'
      -'cacls'

  selection_2:
    CommandLine|contains: 'C:\Windows\Fonts\'
  selection_3:
    CommandLine|contains:
      -'.sh'
      -'.exe'
      -'.dll'
      -'.bin'
      -'.bat'
      -'.cmd'
      -'.js'
      -'.msh'
      -'.reg'
      -'.scr'
      -'.ps'
      -'.vb'
      -'.jar'
      -'.pl'
      -'.inf'
      -'.cpl'
      -'.hta'
      -'.msi'
      -'.vbs'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium