Name:Detect Outlook exe writing a zip file id:a51bfe1a-94f0-4822-b1e4-16ae10145893 version:18 date:None author:Bhavin Patel, Splunk status:production type:Anomaly Description:The following analytic identifies the execution of `outlook.exe` writing a `.zip` file to the disk.
It leverages data from the Endpoint data model, specifically monitoring process and filesystem activities.
This behavior can be significant as it may indicate the use of Outlook to deliver malicious payloads or exfiltrate data via compressed files.
If confirmed malicious, this activity could lead to unauthorized data access, data exfiltration, or the delivery of malware, potentially compromising the security of the affected system and network.
Data_source:
-Sysmon EventID 1 AND Sysmon EventID 11
search:| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime
| rename process_guid as malicious_id | rename parent_process_id as outlook_id
| join malicious_id type=inner [
| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where
Filesystem.file_path=*.zip Filesystem.file_path IN ("*:\\Users*", "*\\AppData\\Local\\Temp*") Filesystem.action=created
by _time span=5m Filesystem.process_guid Filesystem.process_id Filesystem.file_hash Filesystem.dest Filesystem.dvc Filesystem.signature Filesystem.signature_id
| where file_name != "" | `detect_outlook_exe_writing_a_zip_file_filter`
how_to_implement:You must be ingesting data that records filesystem and process activity
from your hosts to populate the Endpoint data model. This is typically populated
via endpoint detection-and-response product, such as Carbon Black, or endpoint data
sources, such as Sysmon.
known_false_positives:It is not uncommon for outlook to write legitimate zip files to the disk. References: -https://www.paubox.com/news/hackers-exploit-corrupted-zip-and-office-files-to-bypass-email-security -https://docs.datadoghq.com/security/default_rules/def-000-14w/ -https://theweborion.com/blog/zip-files/ drilldown_searches: name:'View the detection results for - "$user$" and "$dest$"' search:'%original_detection_search% | search user = "$user$" dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$user$" and "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$", "$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Amadey', 'APT37 Rustonotto and FadeStealer', 'Meduza Stealer', 'PXA Stealer', 'Remcos', 'Spearphishing Attachments']