From b802809a35603848852e5c6908e9a0ecacc74f26 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 5 Oct 2021 14:31:17 -0600 Subject: [PATCH 01/10] Tomorrow Never Haags Malicious InProcServer32 Modification Process Writing DynamicWrapperX Winhlp32 Spawning a Process --- .../malicious_inprocserver32_modification.yml | 72 +++++++++++++++++ .../process_writing_dynamicwrapperx.yml | 79 +++++++++++++++++++ .../endpoint/winhlp32_spawning_a_process.yml | 74 +++++++++++++++++ 3 files changed, 225 insertions(+) create mode 100644 detections/endpoint/malicious_inprocserver32_modification.yml create mode 100644 detections/endpoint/process_writing_dynamicwrapperx.yml create mode 100644 detections/endpoint/winhlp32_spawning_a_process.yml diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml new file mode 100644 index 0000000000..3110c37214 --- /dev/null +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -0,0 +1,72 @@ +name: Malicious InProcServer32 Modification +id: 127c8d08-25ff-11ec-9223-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. + Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\Software\Classes\CLSID or HKCU\Software\Classes\CLSID). Behind the implementation of a COM class is the ‘server’ (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). + During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process. + search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time Processes.process_id Processes.process_name + Processes.dest Processes.process_guid Processes.user + | `drop_dm_object_name(Processes)` + | join process_guid + [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by Registry.registry_path Registry.registry_key_name + Registry.registry_value_name Registry.dest Registry.process_guid Registry.user + | `drop_dm_object_name(Registry)` + | fields _time dest registry_path registry_key_name + registry_value_name process_name process_path process process_guid user] + | stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name registry_path registry_key_name + registry_value_name user + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `malicious_inprocserver32_modification_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. +references: + - https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ + - https://tria.ge/210929-ap75vsddan + - https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Suspicious Regsvr32 Activity + - Remcos + dataset: [] + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.010 + - T1112 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time +- dest +- process_name +- registry_path +- registry_key_name +- registry_value_name +- user + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: The $process_name$ was identified on endpoint $dest$ modifying the registry with a known malicious clsid under InProcServer32. + observable: + - name: dest + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml new file mode 100644 index 0000000000..f154158228 --- /dev/null +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -0,0 +1,79 @@ +name: Process Writing DynamicWrapperX +id: b0a078e4-2601-11ec-9aec-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: Hunting +datamodel: +- Endpoint +description: DynamicWrapperX is an ActiveX component that can be used in a script to call Windows API functions, but it requires the dynwrapx.dll to be installed and registered. With that, a binary writing dynwrapx.dll to disk and registering it into the registry is highly suspect. Why is it needed? In most malicious instances, it will be written to disk at a non-standard location. + During triage, review parallel processes and pivot on the process_guid. Review the registry for any suspicious modifications meant to load dynwrapx.dll. Identify any suspicious module loads of dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time Processes.process_id Processes.process_name + Processes.dest Processes.process_guid Processes.user + | `drop_dm_object_name(Processes)` + | join process_guid + [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="dynwrapx.dll" + by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name + Filesystem.file_path Filesystem.process_guid Filesystem.user + | `drop_dm_object_name(Filesystem)` + | fields _time process_guid file_path file_name file_create_time user dest process_name] + | stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `process_writing_dynamicwrapperx_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter as needed. +references: + - https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ + - https://www.script-coding.com/dynwrapx_eng.html + - https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ + - https://tria.ge/210929-ap75vsddan + - https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Remcos + dataset: [] + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1059 + - T1559.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - process_name + - process_guid + - file_name + - file_path + - file_create_time user + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll + observable: + - name: user + type: User + role: + - Victim + - name: Computer + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml new file mode 100644 index 0000000000..f4d38e56a1 --- /dev/null +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -0,0 +1,74 @@ +name: Winhlp32 Spawning a Process +id: d17dae9e-2618-11ec-b9f5-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: 'The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, spawning a child process that loads a file out of appdata, programdata, or temp. + Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the ".hlp" file name extension. + This particular instance is related to a Remcos sample where dynwrapx.dll is added to the registry under inprocserver32, and later module loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. + During triage, review parallel processes to identify further suspicious behavior. Review module loads for unsuspecting unsigned modules. Capture any file modifications and analyze.' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed. +references: + - https://www.exploit-db.com/exploits/16541 +tags: + analytic_story: + - Remcos + dataset: [] + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1055 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$, and is not typical activity for this process. + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process \ No newline at end of file From 05be27e16a478123ba188bf069185e7b0c02d893 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 5 Oct 2021 14:33:23 -0600 Subject: [PATCH 02/10] fixes --- .../malicious_inprocserver32_modification.yml | 12 ++++++------ .../endpoint/process_writing_dynamicwrapperx.yml | 2 +- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml index 3110c37214..8ce83ad834 100644 --- a/detections/endpoint/malicious_inprocserver32_modification.yml +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -46,12 +46,12 @@ tags: - Splunk Cloud required_fields: - _time -- dest -- process_name -- registry_path -- registry_key_name -- registry_value_name -- user + - dest + - process_name + - registry_path + - registry_key_name + - registry_value_name + - user security_domain: endpoint impact: 80 confidence: 100 diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml index f154158228..6f0802038a 100644 --- a/detections/endpoint/process_writing_dynamicwrapperx.yml +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -59,7 +59,7 @@ tags: context: - Source:Endpoint - Stage:Defense Evasion - message: An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll + message: An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll. observable: - name: user type: User From 8daecc268c765f6782fbeb5cd3817e620f239a6a Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 5 Oct 2021 14:54:17 -0600 Subject: [PATCH 03/10] test files --- detections/endpoint/winhlp32_spawning_a_process.yml | 2 ++ .../malicious_inprocserver32_modification.test.yml | 12 ++++++++++++ .../process_writing_dynamicwrapperx.test.yml | 12 ++++++++++++ tests/endpoint/winhlp32_spawning_a_process.test.yml | 12 ++++++++++++ 4 files changed, 38 insertions(+) create mode 100644 tests/endpoint/malicious_inprocserver32_modification.test.yml create mode 100644 tests/endpoint/process_writing_dynamicwrapperx.test.yml create mode 100644 tests/endpoint/winhlp32_spawning_a_process.test.yml diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml index f4d38e56a1..84f2036943 100644 --- a/detections/endpoint/winhlp32_spawning_a_process.yml +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -21,6 +21,8 @@ how_to_implement: To successfully implement this search you need to be ingesting known_false_positives: False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed. references: - https://www.exploit-db.com/exploits/16541 + - https://tria.ge/210929-ap75vsddan + - https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 tags: analytic_story: - Remcos diff --git a/tests/endpoint/malicious_inprocserver32_modification.test.yml b/tests/endpoint/malicious_inprocserver32_modification.test.yml new file mode 100644 index 0000000000..dd97ac887f --- /dev/null +++ b/tests/endpoint/malicious_inprocserver32_modification.test.yml @@ -0,0 +1,12 @@ +name: Malicious InProcServer32 Modification Unit Test +tests: +- name: Malicious InProcServer32 Modification + file: endpoint/malicious_inprocserver32_modification.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/process_writing_dynamicwrapperx.test.yml b/tests/endpoint/process_writing_dynamicwrapperx.test.yml new file mode 100644 index 0000000000..9b6cdead63 --- /dev/null +++ b/tests/endpoint/process_writing_dynamicwrapperx.test.yml @@ -0,0 +1,12 @@ +name: Process Writing DynamicWrapperX Unit Test +tests: +- name: Process Writing DynamicWrapperX + file: endpoint/process_writing_dynamicwrapperx.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/winhlp32_spawning_a_process.test.yml b/tests/endpoint/winhlp32_spawning_a_process.test.yml new file mode 100644 index 0000000000..ff803d49aa --- /dev/null +++ b/tests/endpoint/winhlp32_spawning_a_process.test.yml @@ -0,0 +1,12 @@ +name: Winhlp32 Spawning a Process Unit Test +tests: +- name: Winhlp32 Spawning a Process + file: endpoint/winhlp32_spawning_a_process.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file From fe02d867a9659881f5e2985e3f7091c45ad9b918 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 5 Oct 2021 14:59:00 -0600 Subject: [PATCH 04/10] fix --- .../endpoint/malicious_inprocserver32_modification.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml index 8ce83ad834..bd76570bd4 100644 --- a/detections/endpoint/malicious_inprocserver32_modification.yml +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -6,10 +6,10 @@ author: Michael Haag, Splunk type: TTP datamodel: - Endpoint -description: The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. - Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\Software\Classes\CLSID or HKCU\Software\Classes\CLSID). Behind the implementation of a COM class is the ‘server’ (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). - During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process. - search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes +description: 'The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. + Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind the implementation of a COM class is the server (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). + During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process.' +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid Processes.user | `drop_dm_object_name(Processes)` From 8181c7d15afb2750d263aa95eb6dc8df8f2ba010 Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 5 Oct 2021 15:02:46 -0600 Subject: [PATCH 05/10] Update malicious_inprocserver32_modification.yml --- detections/endpoint/malicious_inprocserver32_modification.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml index bd76570bd4..f28a776657 100644 --- a/detections/endpoint/malicious_inprocserver32_modification.yml +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -25,7 +25,7 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint | `security_content_ctime(lastTime)` | `malicious_inprocserver32_modification_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. +known_false_positives: False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. It may be required, dependent upon the EDR tool producing registry events, to remove (Default) from the command-line. references: - https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ - https://tria.ge/210929-ap75vsddan From 8cd4c56855194b467129df496cf315e1bd79d99c Mon Sep 17 00:00:00 2001 From: root Date: Tue, 5 Oct 2021 21:23:41 +0000 Subject: [PATCH 06/10] Added detection testing service results inMalicious InProcServer32 Modification --- .../malicious_inprocserver32_modification.yml | 76 +++++++++++-------- 1 file changed, 45 insertions(+), 31 deletions(-) diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml index f28a776657..7e935088fb 100644 --- a/detections/endpoint/malicious_inprocserver32_modification.yml +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -1,40 +1,53 @@ name: Malicious InProcServer32 Modification -id: 127c8d08-25ff-11ec-9223-acde48001122 +id: 127c8d08-25ff-11ec-9223-acde48001122 version: 1 date: '2021-10-05' author: Michael Haag, Splunk type: TTP datamodel: - Endpoint -description: 'The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32. - Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind the implementation of a COM class is the server (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops). - During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process.' +description: The following analytic identifies a process modifying the registry with + a known malicious CLSID under InProcServer32. Most COM classes are registered with + the operating system and are identified by a GUID that represents the Class Identifier + (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind + the implementation of a COM class is the server (some binary) that is referenced + within registry keys under the CLSID. The LocalServer32 key represents a path to + an executable (exe) implementation, and the InprocServer32 key represents a path + to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel + processes for suspicious activity. Pivot on the process GUID to see the full timeline + of events. Analyze the value and look for file modifications. Being this is looking + for inprocserver32, a DLL found in the value will most likely be loaded by a parallel + process. search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time Processes.process_id Processes.process_name - Processes.dest Processes.process_guid Processes.user - | `drop_dm_object_name(Processes)` - | join process_guid - [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by Registry.registry_path Registry.registry_key_name - Registry.registry_value_name Registry.dest Registry.process_guid Registry.user - | `drop_dm_object_name(Registry)` - | fields _time dest registry_path registry_key_name - registry_value_name process_name process_path process process_guid user] - | stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name registry_path registry_key_name - registry_value_name user - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `malicious_inprocserver32_modification_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. It may be required, dependent upon the EDR tool producing registry events, to remove (Default) from the command-line. + by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid + Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats + `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= + "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by + Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest + Registry.process_guid Registry.user | `drop_dm_object_name(Registry)` | fields _time + dest registry_path registry_key_name registry_value_name process_name process_path + process process_guid user] | stats count min(_time) as firstTime max(_time) as lastTime + by dest, process_name registry_path registry_key_name registry_value_name user | + `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `malicious_inprocserver32_modification_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited, filter as needed. In our + test case, Remcos used regsvr32.exe to modify the registry. It may be required, + dependent upon the EDR tool producing registry events, to remove (Default) from + the command-line. references: - - https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ - - https://tria.ge/210929-ap75vsddan - - https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 tags: analytic_story: - Suspicious Regsvr32 Activity - Remcos - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log kill_chain_phases: - Exploitation mitre_attack_id: @@ -47,20 +60,20 @@ tags: required_fields: - _time - dest - - process_name - - registry_path + - process_name + - registry_path - registry_key_name - - registry_value_name - - user + - registry_value_name + - user security_domain: endpoint impact: 80 confidence: 100 - # (impact * confidence)/100 risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion - message: The $process_name$ was identified on endpoint $dest$ modifying the registry with a known malicious clsid under InProcServer32. + message: The $process_name$ was identified on endpoint $dest$ modifying the registry + with a known malicious clsid under InProcServer32. observable: - name: dest type: Hostname @@ -69,4 +82,5 @@ tags: - name: process_name type: Process role: - - Child Process \ No newline at end of file + - Child Process + automated_detection_testing: passed From 87d7b8a114448aa9eb6715e6cba79fdb79cfc37b Mon Sep 17 00:00:00 2001 From: root Date: Tue, 5 Oct 2021 21:27:14 +0000 Subject: [PATCH 07/10] Added detection testing service results inWinhlp32 Spawning a Process --- .../endpoint/winhlp32_spawning_a_process.yml | 58 +++++++++++-------- 1 file changed, 35 insertions(+), 23 deletions(-) diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml index 84f2036943..b549589720 100644 --- a/detections/endpoint/winhlp32_spawning_a_process.yml +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -6,27 +6,38 @@ author: Michael Haag, Splunk type: TTP datamodel: - Endpoint -description: 'The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, spawning a child process that loads a file out of appdata, programdata, or temp. - Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the ".hlp" file name extension. - This particular instance is related to a Remcos sample where dynwrapx.dll is added to the registry under inprocserver32, and later module loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. - During triage, review parallel processes to identify further suspicious behavior. Review module loads for unsuspecting unsigned modules. Capture any file modifications and analyze.' +description: The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, + spawning a child process that loads a file out of appdata, programdata, or temp. + Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added + to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the + ".hlp" file name extension. This particular instance is related to a Remcos sample + where dynwrapx.dll is added to the registry under inprocserver32, and later module + loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During + triage, review parallel processes to identify further suspicious behavior. Review + module loads for unsuspecting unsigned modules. Capture any file modifications and + analyze. search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") - by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name - Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed. + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe + Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest + Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited as winhlp32.exe is typically + not used with the latest flavors of Windows OS. However, filter as needed. references: - - https://www.exploit-db.com/exploits/16541 - - https://tria.ge/210929-ap75vsddan - - https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +- https://www.exploit-db.com/exploits/16541 +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 tags: analytic_story: - Remcos - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log kill_chain_phases: - Exploitation mitre_attack_id: @@ -39,11 +50,11 @@ tags: - _time - Processes.dest - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline + - Processes.parent_process_name + - Processes.parent_process - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline + - Processes.process_name + - Processes.process - Processes.process_id - Processes.parent_process_path - Processes.process_path @@ -51,12 +62,12 @@ tags: security_domain: endpoint impact: 80 confidence: 100 - # (impact * confidence)/100 risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion - message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$, and is not typical activity for this process. + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$, and is not typical activity for this process. observable: - name: user type: User @@ -73,4 +84,5 @@ tags: - name: process_name type: Process role: - - Child Process \ No newline at end of file + - Child Process + automated_detection_testing: passed From fa190b9700dd1575a8219c76f7e91315d534ed27 Mon Sep 17 00:00:00 2001 From: root Date: Tue, 5 Oct 2021 21:28:04 +0000 Subject: [PATCH 08/10] Added detection testing service results inProcess Writing DynamicWrapperX --- .../process_writing_dynamicwrapperx.yml | 69 +++++++++++-------- 1 file changed, 40 insertions(+), 29 deletions(-) diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml index 6f0802038a..98807996a2 100644 --- a/detections/endpoint/process_writing_dynamicwrapperx.yml +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -6,34 +6,44 @@ author: Michael Haag, Splunk type: Hunting datamodel: - Endpoint -description: DynamicWrapperX is an ActiveX component that can be used in a script to call Windows API functions, but it requires the dynwrapx.dll to be installed and registered. With that, a binary writing dynwrapx.dll to disk and registering it into the registry is highly suspect. Why is it needed? In most malicious instances, it will be written to disk at a non-standard location. - During triage, review parallel processes and pivot on the process_guid. Review the registry for any suspicious modifications meant to load dynwrapx.dll. Identify any suspicious module loads of dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. +description: DynamicWrapperX is an ActiveX component that can be used in a script + to call Windows API functions, but it requires the dynwrapx.dll to be installed + and registered. With that, a binary writing dynwrapx.dll to disk and registering + it into the registry is highly suspect. Why is it needed? In most malicious instances, + it will be written to disk at a non-standard location. During triage, review parallel + processes and pivot on the process_guid. Review the registry for any suspicious + modifications meant to load dynwrapx.dll. Identify any suspicious module loads of + dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes - by _time Processes.process_id Processes.process_name - Processes.dest Processes.process_guid Processes.user - | `drop_dm_object_name(Processes)` - | join process_guid - [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="dynwrapx.dll" - by _time Filesystem.dest Filesystem.file_create_time Filesystem.file_name - Filesystem.file_path Filesystem.process_guid Filesystem.user - | `drop_dm_object_name(Filesystem)` - | fields _time process_guid file_path file_name file_create_time user dest process_name] - | stats count min(_time) as firstTime max(_time) as lastTime by dest process_name process_guid file_name file_path file_create_time user - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` + by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid + Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats + `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where + Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time + Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user + | `drop_dm_object_name(Filesystem)` | fields _time process_guid file_path file_name + file_create_time user dest process_name] | stats count min(_time) as firstTime max(_time) + as lastTime by dest process_name process_guid file_name file_path file_create_time + user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `process_writing_dynamicwrapperx_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter as needed. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` + node. In addition, confirm the latest CIM App 4.20 or higher is installed and the + latest TA for the endpoint product. +known_false_positives: False positives should be limited, however it is possible to + filter by Processes.process_name and specific processes (ex. wscript.exe). Filter + as needed. references: - - https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ - - https://www.script-coding.com/dynwrapx_eng.html - - https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ - - https://tria.ge/210929-ap75vsddan - - https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +- https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ +- https://www.script-coding.com/dynwrapx_eng.html +- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 tags: analytic_story: - Remcos - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log kill_chain_phases: - Exploitation mitre_attack_id: @@ -45,21 +55,21 @@ tags: - Splunk Cloud required_fields: - _time - - dest - - process_name - - process_guid - - file_name + - dest + - process_name + - process_guid + - file_name - file_path - file_create_time user security_domain: endpoint impact: 80 confidence: 100 - # (impact * confidence)/100 risk_score: 80 context: - Source:Endpoint - Stage:Defense Evasion - message: An instance of $process_name$ was identified on endpoint $dest$ downloading the DynamicWrapperX dll. + message: An instance of $process_name$ was identified on endpoint $dest$ downloading + the DynamicWrapperX dll. observable: - name: user type: User @@ -76,4 +86,5 @@ tags: - name: process_name type: Process role: - - Child Process \ No newline at end of file + - Child Process + automated_detection_testing: passed From 1e18798bb75b0c1cd9e8c360b0814a6c22391f7f Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Wed, 6 Oct 2021 10:01:44 -0600 Subject: [PATCH 09/10] Update process_writing_dynamicwrapperx.yml --- detections/endpoint/process_writing_dynamicwrapperx.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml index 98807996a2..2acf492064 100644 --- a/detections/endpoint/process_writing_dynamicwrapperx.yml +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -32,7 +32,7 @@ how_to_implement: To successfully implement this search you need to be ingesting latest TA for the endpoint product. known_false_positives: False positives should be limited, however it is possible to filter by Processes.process_name and specific processes (ex. wscript.exe). Filter - as needed. + as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). references: - https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ - https://www.script-coding.com/dynwrapx_eng.html From c059b05588b9d8b353ad086c0ef6eb183ab4c5ed Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Wed, 6 Oct 2021 15:39:16 -0700 Subject: [PATCH 10/10] Update process_writing_dynamicwrapperx.yml minor --- detections/endpoint/process_writing_dynamicwrapperx.yml | 6 +----- 1 file changed, 1 insertion(+), 5 deletions(-) diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml index 2acf492064..bea147733f 100644 --- a/detections/endpoint/process_writing_dynamicwrapperx.yml +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -75,14 +75,10 @@ tags: type: User role: - Victim - - name: Computer + - name: dest type: Hostname role: - Victim - - name: parent_process_name - type: Parent Process - role: - - Parent Process - name: process_name type: Process role: