Merge branch 'pterodactyl' of https://github.com/splunk/security_content into pterodactyl

This commit is contained in:
Detection Testing Service
2021-10-05 21:28:05 +00:00
2 changed files with 80 additions and 54 deletions
@@ -1,40 +1,53 @@
name: Malicious InProcServer32 Modification
id: 127c8d08-25ff-11ec-9223-acde48001122
id: 127c8d08-25ff-11ec-9223-acde48001122
version: 1
date: '2021-10-05'
author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: 'The following analytic identifies a process modifying the registry with a known malicious CLSID under InProcServer32.
Most COM classes are registered with the operating system and are identified by a GUID that represents the Class Identifier (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind the implementation of a COM class is the server (some binary) that is referenced within registry keys under the CLSID. The LocalServer32 key represents a path to an executable (exe) implementation, and the InprocServer32 key represents a path to a dynamic link library (DLL) implementation (Bohops).
During triage, review parallel processes for suspicious activity. Pivot on the process GUID to see the full timeline of events. Analyze the value and look for file modifications. Being this is looking for inprocserver32, a DLL found in the value will most likely be loaded by a parallel process.'
description: The following analytic identifies a process modifying the registry with
a known malicious CLSID under InProcServer32. Most COM classes are registered with
the operating system and are identified by a GUID that represents the Class Identifier
(CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind
the implementation of a COM class is the server (some binary) that is referenced
within registry keys under the CLSID. The LocalServer32 key represents a path to
an executable (exe) implementation, and the InprocServer32 key represents a path
to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel
processes for suspicious activity. Pivot on the process GUID to see the full timeline
of events. Analyze the value and look for file modifications. Being this is looking
for inprocserver32, a DLL found in the value will most likely be loaded by a parallel
process.
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
by _time Processes.process_id Processes.process_name
Processes.dest Processes.process_guid Processes.user
| `drop_dm_object_name(Processes)`
| join process_guid
[| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by Registry.registry_path Registry.registry_key_name
Registry.registry_value_name Registry.dest Registry.process_guid Registry.user
| `drop_dm_object_name(Registry)`
| fields _time dest registry_path registry_key_name
registry_value_name process_name process_path process process_guid user]
| stats count min(_time) as firstTime max(_time) as lastTime by dest, process_name registry_path registry_key_name
registry_value_name user
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `malicious_inprocserver32_modification_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives should be limited, filter as needed. In our test case, Remcos used regsvr32.exe to modify the registry. It may be required, dependent upon the EDR tool producing registry events, to remove (Default) from the command-line.
by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid
Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats
`security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path=
"*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by
Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest
Registry.process_guid Registry.user | `drop_dm_object_name(Registry)` | fields _time
dest registry_path registry_key_name registry_value_name process_name process_path
process process_guid user] | stats count min(_time) as firstTime max(_time) as lastTime
by dest, process_name registry_path registry_key_name registry_value_name user |
`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `malicious_inprocserver32_modification_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives should be limited, filter as needed. In our
test case, Remcos used regsvr32.exe to modify the registry. It may be required,
dependent upon the EDR tool producing registry events, to remove (Default) from
the command-line.
references:
- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/
- https://tria.ge/210929-ap75vsddan
- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89
- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/
- https://tria.ge/210929-ap75vsddan
- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89
tags:
analytic_story:
- Suspicious Regsvr32 Activity
- Remcos
dataset: []
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -47,20 +60,20 @@ tags:
required_fields:
- _time
- dest
- process_name
- registry_path
- process_name
- registry_path
- registry_key_name
- registry_value_name
- user
- registry_value_name
- user
security_domain: endpoint
impact: 80
confidence: 100
# (impact * confidence)/100
risk_score: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
message: The $process_name$ was identified on endpoint $dest$ modifying the registry with a known malicious clsid under InProcServer32.
message: The $process_name$ was identified on endpoint $dest$ modifying the registry
with a known malicious clsid under InProcServer32.
observable:
- name: dest
type: Hostname
@@ -69,4 +82,5 @@ tags:
- name: process_name
type: Process
role:
- Child Process
- Child Process
automated_detection_testing: passed
@@ -6,27 +6,38 @@ author: Michael Haag, Splunk
type: TTP
datamodel:
- Endpoint
description: 'The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, spawning a child process that loads a file out of appdata, programdata, or temp.
Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the ".hlp" file name extension.
This particular instance is related to a Remcos sample where dynwrapx.dll is added to the registry under inprocserver32, and later module loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk.
During triage, review parallel processes to identify further suspicious behavior. Review module loads for unsuspecting unsigned modules. Capture any file modifications and analyze.'
description: The following analytic identifies winhlp32.exe, found natively in `c:\windows\`,
spawning a child process that loads a file out of appdata, programdata, or temp.
Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added
to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the
".hlp" file name extension. This particular instance is related to a Remcos sample
where dynwrapx.dll is added to the registry under inprocserver32, and later module
loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During
triage, review parallel processes to identify further suspicious behavior. Review
module loads for unsuspecting unsigned modules. Capture any file modifications and
analyze.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*")
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id
| `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
known_false_positives: False positives should be limited as winhlp32.exe is typically not used with the latest flavors of Windows OS. However, filter as needed.
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe
Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest
Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
confirm the latest CIM App 4.20 or higher is installed and the latest TA for the
endpoint product.
known_false_positives: False positives should be limited as winhlp32.exe is typically
not used with the latest flavors of Windows OS. However, filter as needed.
references:
- https://www.exploit-db.com/exploits/16541
- https://tria.ge/210929-ap75vsddan
- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89
- https://www.exploit-db.com/exploits/16541
- https://tria.ge/210929-ap75vsddan
- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89
tags:
analytic_story:
- Remcos
dataset: []
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -39,11 +50,11 @@ tags:
- _time
- Processes.dest
- Processes.user
- Processes.parent_process_name #parent process name
- Processes.parent_process #parent cmdline
- Processes.parent_process_name
- Processes.parent_process
- Processes.original_file_name
- Processes.process_name #process name
- Processes.process #process cmdline
- Processes.process_name
- Processes.process
- Processes.process_id
- Processes.parent_process_path
- Processes.process_path
@@ -51,12 +62,12 @@ tags:
security_domain: endpoint
impact: 80
confidence: 100
# (impact * confidence)/100
risk_score: 80
context:
- Source:Endpoint
- Stage:Defense Evasion
message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$, and is not typical activity for this process.
message: An instance of $parent_process_name$ spawning $process_name$ was identified
on endpoint $dest$, and is not typical activity for this process.
observable:
- name: user
type: User
@@ -73,4 +84,5 @@ tags:
- name: process_name
type: Process
role:
- Child Process
- Child Process
automated_detection_testing: passed