diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml new file mode 100644 index 0000000000..7e935088fb --- /dev/null +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -0,0 +1,86 @@ +name: Malicious InProcServer32 Modification +id: 127c8d08-25ff-11ec-9223-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies a process modifying the registry with + a known malicious CLSID under InProcServer32. Most COM classes are registered with + the operating system and are identified by a GUID that represents the Class Identifier + (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind + the implementation of a COM class is the server (some binary) that is referenced + within registry keys under the CLSID. The LocalServer32 key represents a path to + an executable (exe) implementation, and the InprocServer32 key represents a path + to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel + processes for suspicious activity. Pivot on the process GUID to see the full timeline + of events. Analyze the value and look for file modifications. Being this is looking + for inprocserver32, a DLL found in the value will most likely be loaded by a parallel + process. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid + Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats + `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= + "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by + Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest + Registry.process_guid Registry.user | `drop_dm_object_name(Registry)` | fields _time + dest registry_path registry_key_name registry_value_name process_name process_path + process process_guid user] | stats count min(_time) as firstTime max(_time) as lastTime + by dest, process_name registry_path registry_key_name registry_value_name user | + `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `malicious_inprocserver32_modification_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited, filter as needed. In our + test case, Remcos used regsvr32.exe to modify the registry. It may be required, + dependent upon the EDR tool producing registry events, to remove (Default) from + the command-line. +references: +- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Suspicious Regsvr32 Activity + - Remcos + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.010 + - T1112 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - process_name + - registry_path + - registry_key_name + - registry_value_name + - user + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: The $process_name$ was identified on endpoint $dest$ modifying the registry + with a known malicious clsid under InProcServer32. + observable: + - name: dest + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + automated_detection_testing: passed diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml new file mode 100644 index 0000000000..bea147733f --- /dev/null +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -0,0 +1,86 @@ +name: Process Writing DynamicWrapperX +id: b0a078e4-2601-11ec-9aec-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: Hunting +datamodel: +- Endpoint +description: DynamicWrapperX is an ActiveX component that can be used in a script + to call Windows API functions, but it requires the dynwrapx.dll to be installed + and registered. With that, a binary writing dynwrapx.dll to disk and registering + it into the registry is highly suspect. Why is it needed? In most malicious instances, + it will be written to disk at a non-standard location. During triage, review parallel + processes and pivot on the process_guid. Review the registry for any suspicious + modifications meant to load dynwrapx.dll. Identify any suspicious module loads of + dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid + Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats + `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where + Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time + Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user + | `drop_dm_object_name(Filesystem)` | fields _time process_guid file_path file_name + file_create_time user dest process_name] | stats count min(_time) as firstTime max(_time) + as lastTime by dest process_name process_guid file_name file_path file_create_time + user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `process_writing_dynamicwrapperx_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` + node. In addition, confirm the latest CIM App 4.20 or higher is installed and the + latest TA for the endpoint product. +known_false_positives: False positives should be limited, however it is possible to + filter by Processes.process_name and specific processes (ex. wscript.exe). Filter + as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). +references: +- https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ +- https://www.script-coding.com/dynwrapx_eng.html +- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Remcos + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1059 + - T1559.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - process_name + - process_guid + - file_name + - file_path + - file_create_time user + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $process_name$ was identified on endpoint $dest$ downloading + the DynamicWrapperX dll. + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + automated_detection_testing: passed diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml new file mode 100644 index 0000000000..b549589720 --- /dev/null +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -0,0 +1,88 @@ +name: Winhlp32 Spawning a Process +id: d17dae9e-2618-11ec-b9f5-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, + spawning a child process that loads a file out of appdata, programdata, or temp. + Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added + to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the + ".hlp" file name extension. This particular instance is related to a Remcos sample + where dynwrapx.dll is added to the registry under inprocserver32, and later module + loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During + triage, review parallel processes to identify further suspicious behavior. Review + module loads for unsuspecting unsigned modules. Capture any file modifications and + analyze. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe + Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest + Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited as winhlp32.exe is typically + not used with the latest flavors of Windows OS. However, filter as needed. +references: +- https://www.exploit-db.com/exploits/16541 +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Remcos + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1055 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$, and is not typical activity for this process. + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + automated_detection_testing: passed diff --git a/tests/endpoint/malicious_inprocserver32_modification.test.yml b/tests/endpoint/malicious_inprocserver32_modification.test.yml new file mode 100644 index 0000000000..dd97ac887f --- /dev/null +++ b/tests/endpoint/malicious_inprocserver32_modification.test.yml @@ -0,0 +1,12 @@ +name: Malicious InProcServer32 Modification Unit Test +tests: +- name: Malicious InProcServer32 Modification + file: endpoint/malicious_inprocserver32_modification.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/process_writing_dynamicwrapperx.test.yml b/tests/endpoint/process_writing_dynamicwrapperx.test.yml new file mode 100644 index 0000000000..9b6cdead63 --- /dev/null +++ b/tests/endpoint/process_writing_dynamicwrapperx.test.yml @@ -0,0 +1,12 @@ +name: Process Writing DynamicWrapperX Unit Test +tests: +- name: Process Writing DynamicWrapperX + file: endpoint/process_writing_dynamicwrapperx.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/winhlp32_spawning_a_process.test.yml b/tests/endpoint/winhlp32_spawning_a_process.test.yml new file mode 100644 index 0000000000..ff803d49aa --- /dev/null +++ b/tests/endpoint/winhlp32_spawning_a_process.test.yml @@ -0,0 +1,12 @@ +name: Winhlp32 Spawning a Process Unit Test +tests: +- name: Winhlp32 Spawning a Process + file: endpoint/winhlp32_spawning_a_process.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file