This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Proxy Execution Via Wuauclt.EXE
Original Source:
[Sigma source]
Title:
Proxy Execution Via Wuauclt.EXE
Status:
test
Description:
Detects the use of the Windows Update Client binary (wuauclt.exe) for proxy execution.
References:
-https://dtm.uk/wuauclt/
-https://blog.malwarebytes.com/threat-intelligence/2022/01/north-koreas-lazarus-apt-leverages-windows-update-client-github-in-latest-campaign/
Author:
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Florian Roth (Nextron Systems), Sreeman, FPT.EagleEye Team
Date:
2020-10-12
modified:
2023-11-11
Tags:
-'attack.stealth'
-'attack.t1218'
-'attack.execution'
Logsource:
category: process_creation
product: windows
Detection:
selection_img:
Image|endswith
:
'\wuauclt.exe'
OriginalFileName
:
'wuauclt.exe'
selection_cli:
CommandLine|contains|all
:
-'UpdateDeploymentProvider'
-'RunHandlerComServer'
filter_main_generic:
CommandLine|contains
:
' /UpdateDeploymentProvider UpdateDeploymentProvider.dll '
filter_main_wuaueng:
CommandLine|contains
:
' wuaueng.dll '
filter_main_uus:
CommandLine|contains
:
-':\Windows\UUS\Packages\Preview\amd64\updatedeploy.dll /ClassId'
-':\Windows\UUS\amd64\UpdateDeploy.dll /ClassId'
filter_main_winsxs:
CommandLine|contains|all
:
-':\Windows\WinSxS\'
-'\UpdateDeploy.dll /ClassId '
condition
:
all of selection_* and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high