Suspicious WMIC Execution Via Office Process

 Original Source: [Sigma source]
Title: Suspicious WMIC Execution Via Office Process
Status: test
Description:Office application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).
References:
  -https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
  -https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
Author: Vadim Khrykov, Cyb3rEng
Date: 2021-08-23
modified:2023-02-14
Tags:
  • -'attack.stealth'
  • -'attack.t1204.002'
  • -'attack.t1047'
  • -'attack.t1218.010'
  • -'attack.execution'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_parent:
    ParentImage|endswith:
      -'\WINWORD.EXE'
      -'\EXCEL.EXE'
      -'\POWERPNT.exe'
      -'\MSPUB.exe'
      -'\VISIO.exe'
      -'\MSACCESS.EXE'
      -'\EQNEDT32.EXE'
      -'\ONENOTE.EXE'
      -'\wordpad.exe'
      -'\wordview.exe'

  selection_wmic_img:
Image|endswith:'\wbem\WMIC.exe' OriginalFileName:'wmic.exe'   selection_wmic_cli:
    CommandLine|contains|all:
      -'process'
      -'create'
      -'call'

    CommandLine|contains:
      -'regsvr32'
      -'rundll32'
      -'msiexec'
      -'mshta'
      -'verclsid'
      -'wscript'
      -'cscript'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high