Suspicious Shim Database Patching Activity

 Original Source: [Sigma source]
Title: Suspicious Shim Database Patching Activity
Status: test
Description:Detects installation of new shim databases that try to patch sections of known processes for potential process injection or persistence.
References:
  -https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/pillowmint-fin7s-monkey-thief/
  -https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-08-01
modified:2023-12-06
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.011'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject|contains: '\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\'
    TargetObject|endswith:
      -'\csrss.exe'
      -'\dllhost.exe'
      -'\explorer.exe'
      -'\RuntimeBroker.exe'
      -'\services.exe'
      -'\sihost.exe'
      -'\svchost.exe'
      -'\taskhostw.exe'
      -'\winlogon.exe'
      -'\WmiPrvSe.exe'

  condition:selection
Falsepositives:
  -Unknown
Level: high