Suspicious New Service Creation

 Original Source: [Sigma source]
Title: Suspicious New Service Creation
Status: test
Description:Detects creation of a new service via "sc" command or the powershell "new-service" cmdlet with suspicious binary paths
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md
  -https://web.archive.org/web/20180331144337/https://www.fireeye.com/blog/threat-research/2018/03/sanny-malware-delivery-method-updated-in-recently-observed-attacks.html
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-14
modified:2022-11-18
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1543.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_sc:
    Image|endswith: '\sc.exe'
    CommandLine|contains|all:
      -'create'
      -'binPath='

  selection_posh:
    CommandLine|contains|all:
      -'New-Service'
      -'-BinaryPathName'

  susp_binpath:
    CommandLine|contains:
      -'powershell'
      -'mshta'
      -'wscript'
      -'cscript'
      -'svchost'
      -'dllhost'
      -'cmd '
      -'cmd.exe /c'
      -'cmd.exe /k'
      -'cmd.exe /r'
      -'rundll32'
      -'C:\Users\Public'
      -'\Downloads\'
      -'\Desktop\'
      -'\Microsoft\Windows\Start Menu\Programs\Startup\'
      -'C:\Windows\TEMP\'
      -'\AppData\Local\Temp'

  condition:1 of selection* and susp_binpath
Falsepositives:
  -Unlikely
Level: high