This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Chopper Webshell Process Pattern
Original Source:
[Sigma source]
Title:
Chopper Webshell Process Pattern
Status:
test
Description:
Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
References:
-https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
Author:
Florian Roth (Nextron Systems), MSTI (query)
Date:
2022-10-01
modified:
None
Tags:
-'attack.persistence'
-'attack.discovery'
-'attack.t1505.003'
-'attack.t1018'
-'attack.t1033'
-'attack.t1087'
Logsource:
category: process_creation
product: windows
Detection:
selection_origin:
Image|endswith
:
'\w3wp.exe'
ParentImage|endswith
:
'\w3wp.exe'
selection_cmdline:
CommandLine|contains
:
-'&ipconfig&echo'
-'&quser&echo'
-'&whoami&echo'
-'&c:&echo'
-'&cd&echo'
-'&dir&echo'
-'&echo [E]'
-'&echo [S]'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high