Chopper Webshell Process Pattern

 Original Source: [Sigma source]
Title: Chopper Webshell Process Pattern
Status: test
Description:Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
References:
  -https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
Author: Florian Roth (Nextron Systems), MSTI (query)
Date: 2022-10-01
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.discovery'
  • -'attack.t1505.003'
  • -'attack.t1018'
  • -'attack.t1033'
  • -'attack.t1087'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_origin:
Image|endswith:'\w3wp.exe' ParentImage|endswith:'\w3wp.exe'   selection_cmdline:
    CommandLine|contains:
      -'&ipconfig&echo'
      -'&quser&echo'
      -'&whoami&echo'
      -'&c:&echo'
      -'&cd&echo'
      -'&dir&echo'
      -'&echo [E]'
      -'&echo [S]'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high