Suspicious WmiPrvSE Child Process

 Original Source: [Sigma source]
Title: Suspicious WmiPrvSE Child Process
Status: test
Description:Detects suspicious and uncommon child processes of WmiPrvSE
References:
  -https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/
  -https://github.com/vadim-hunter/Detection-Ideas-Rules/blob/02bcbfc2bfb8b4da601bb30de0344ae453aa1afe/Threat%20Intelligence/The%20DFIR%20Report/20210329_Sodinokibi_(aka_REvil)_Ransomware.yaml
  -https://blog.osarmor.com/319/onenote-attachment-delivers-asyncrat-malware/
  -https://twitter.com/ForensicITGuy/status/1334734244120309760
Author: Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems)
Date: 2021-08-23
modified:2023-11-10
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1047'
  • -'attack.t1204.002'
  • -'attack.t1218.010'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_parent:
    ParentImage|endswith: '\wbem\WmiPrvSE.exe'
  selection_children_1:
    Image|endswith:
      -'\certutil.exe'
      -'\cscript.exe'
      -'\mshta.exe'
      -'\msiexec.exe'
      -'\regsvr32.exe'
      -'\rundll32.exe'
      -'\verclsid.exe'
      -'\wscript.exe'

  selection_children_2:
    Image|endswith: '\cmd.exe'
    CommandLine|contains:
      -'cscript'
      -'mshta'
      -'powershell'
      -'pwsh'
      -'regsvr32'
      -'rundll32'
      -'wscript'

  filter_main_werfault:
    Image|endswith: '\WerFault.exe'
  filter_main_wmiprvse:
    Image|endswith: '\WmiPrvSE.exe'
  filter_main_msiexec:
    Image|endswith: '\msiexec.exe'
    CommandLine|contains: '/i '
  condition:selection_parent and 1 of selection_children_* and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high