Branch was auto-updated.

This commit is contained in:
Bhavin Patel
2021-10-13 05:54:02 -07:00
committed by GitHub
6 changed files with 296 additions and 0 deletions
@@ -0,0 +1,86 @@
name: Malicious InProcServer32 Modification
id: 127c8d08-25ff-11ec-9223-acde48001122
version: 1
date: '2021-10-05'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies a process modifying the registry with
a known malicious CLSID under InProcServer32. Most COM classes are registered with
the operating system and are identified by a GUID that represents the Class Identifier
(CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind
the implementation of a COM class is the server (some binary) that is referenced
within registry keys under the CLSID. The LocalServer32 key represents a path to
an executable (exe) implementation, and the InprocServer32 key represents a path
to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel
processes for suspicious activity. Pivot on the process GUID to see the full timeline
of events. Analyze the value and look for file modifications. Being this is looking
for inprocserver32, a DLL found in the value will most likely be loaded by a parallel
process.
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid
Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats
`security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path=
"*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest
Registry.process_guid Registry.user | `drop_dm_object_name(Registry)` | fields _time
dest registry_path registry_key_name registry_value_name process_name process_path
process process_guid user] | stats count min(_time) as firstTime max(_time) as lastTime
by dest, process_name registry_path registry_key_name registry_value_name user |
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `malicious_inprocserver32_modification_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives should be limited, filter as needed. In our
test case, Remcos used regsvr32.exe to modify the registry. It may be required,
dependent upon the EDR tool producing registry events, to remove (Default) from
the command-line.
references:
- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/
- https://tria.ge/210929-ap75vsddan
- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89
tags:
analytic_story:
- Suspicious Regsvr32 Activity
- Remcos
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1218.010
- T1112
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- dest
- process_name
- registry_path
- registry_key_name
- registry_value_name
- user
security_domain: endpoint
impact: 80
confidence: 100
risk_score: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
message: The $process_name$ was identified on endpoint $dest$ modifying the registry
with a known malicious clsid under InProcServer32.
observable:
- name: dest
type: Hostname
role:
- Victim
- name: process_name
type: Process
role:
- Child Process
automated_detection_testing: passed
@@ -0,0 +1,86 @@
name: Process Writing DynamicWrapperX
id: b0a078e4-2601-11ec-9aec-acde48001122
version: 1
date: '2021-10-05'
author: Michael Haag, Splunk
type: Hunting
datamodel:
- Endpoint
description: DynamicWrapperX is an ActiveX component that can be used in a script
to call Windows API functions, but it requires the dynwrapx.dll to be installed
and registered. With that, a binary writing dynwrapx.dll to disk and registering
it into the registry is highly suspect. Why is it needed? In most malicious instances,
it will be written to disk at a non-standard location. During triage, review parallel
processes and pivot on the process_guid. Review the registry for any suspicious
modifications meant to load dynwrapx.dll. Identify any suspicious module loads of
dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript.
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid
Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats
`security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where
Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time
Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user
| `drop_dm_object_name(Filesystem)` | fields _time process_guid file_path file_name
file_create_time user dest process_name] | stats count min(_time) as firstTime max(_time)
as lastTime by dest process_name process_guid file_name file_path file_create_time
user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `process_writing_dynamicwrapperx_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem`
node. In addition, confirm the latest CIM App 4.20 or higher is installed and the
latest TA for the endpoint product.
known_false_positives: False positives should be limited, however it is possible to
filter by Processes.process_name and specific processes (ex. wscript.exe). Filter
as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default).
references:
- https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/
- https://www.script-coding.com/dynwrapx_eng.html
- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/
- https://tria.ge/210929-ap75vsddan
- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89
tags:
analytic_story:
- Remcos
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1059
- T1559.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- dest
- process_name
- process_guid
- file_name
- file_path
- file_create_time user
security_domain: endpoint
impact: 80
confidence: 100
risk_score: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
message: An instance of $process_name$ was identified on endpoint $dest$ downloading
the DynamicWrapperX dll.
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: process_name
type: Process
role:
- Child Process
automated_detection_testing: passed
@@ -0,0 +1,88 @@
name: Winhlp32 Spawning a Process
id: d17dae9e-2618-11ec-b9f5-acde48001122
version: 1
date: '2021-10-05'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: The following analytic identifies winhlp32.exe, found natively in `c:\windows\`,
spawning a child process that loads a file out of appdata, programdata, or temp.
Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added
to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the
".hlp" file name extension. This particular instance is related to a Remcos sample
where dynwrapx.dll is added to the registry under inprocserver32, and later module
loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During
triage, review parallel processes to identify further suspicious behavior. Review
module loads for unsuspecting unsigned modules. Capture any file modifications and
analyze.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe
Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest
Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives should be limited as winhlp32.exe is typically
not used with the latest flavors of Windows OS. However, filter as needed.
references:
- https://www.exploit-db.com/exploits/16541
- https://tria.ge/210929-ap75vsddan
- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89
tags:
analytic_story:
- Remcos
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1055
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
- Processes.parent_process_id
security_domain: endpoint
impact: 80
confidence: 100
risk_score: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$, and is not typical activity for this process.
observable:
- name: user
type: User
role:
- Victim
- name: dest
type: Hostname
role:
- Victim
- name: parent_process_name
type: Parent Process
role:
- Parent Process
- name: process_name
type: Process
role:
- Child Process
automated_detection_testing: passed
@@ -0,0 +1,12 @@
name: Malicious InProcServer32 Modification Unit Test
tests:
- name: Malicious InProcServer32 Modification
file: endpoint/malicious_inprocserver32_modification.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Process Writing DynamicWrapperX Unit Test
tests:
- name: Process Writing DynamicWrapperX
file: endpoint/process_writing_dynamicwrapperx.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Winhlp32 Spawning a Process Unit Test
tests:
- name: Winhlp32 Spawning a Process
file: endpoint/winhlp32_spawning_a_process.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog