This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious WMIC Execution Via Office Process
Original Source:
[Sigma source]
Title:
Suspicious WMIC Execution Via Office Process
Status:
test
Description:
Office application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).
References:
-https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
-https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
Author:
Vadim Khrykov, Cyb3rEng
Date:
2021-08-23
modified:
2023-02-14
Tags:
-'attack.stealth'
-'attack.t1204.002'
-'attack.t1047'
-'attack.t1218.010'
-'attack.execution'
Logsource:
product: windows
category: process_creation
Detection:
selection_parent:
ParentImage|endswith
:
-'\WINWORD.EXE'
-'\EXCEL.EXE'
-'\POWERPNT.exe'
-'\MSPUB.exe'
-'\VISIO.exe'
-'\MSACCESS.EXE'
-'\EQNEDT32.EXE'
-'\ONENOTE.EXE'
-'\wordpad.exe'
-'\wordview.exe'
selection_wmic_img:
Image|endswith
:
'\wbem\WMIC.exe'
OriginalFileName
:
'wmic.exe'
selection_wmic_cli:
CommandLine|contains|all
:
-'process'
-'create'
-'call'
CommandLine|contains
:
-'regsvr32'
-'rundll32'
-'msiexec'
-'mshta'
-'verclsid'
-'wscript'
-'cscript'
condition
:
all of selection_*
Falsepositives:
-Unknown
Level:
high