name: Suspicious Process File Path id: 9be25988-ad82-11eb-a14f-acde48001122 version: 1 date: '2021-05-05' author: Teoderick Contreras, Splunk type: TTP datamodel: - Endpoint description: The following analytic will detect a suspicious process running in a file path where a process is not commonly seen and is most commonly used by malicious software. This behavior has been used by adversaries where they drop and run an exe in a path that is accessible without admin privileges. search: '| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\windows\\fonts\\*" OR Processes.process_path = "*\\windows\\temp\\*" OR Processes.process_path = "*\\users\\public\\*" OR Processes.process_path = "*\\windows\\debug\\*" OR Processes.process_path.file_path = "*\\Users\\Administrator\\Music\\*" OR Processes.process_path.file_path = "*\\Windows\\servicing\\*" OR Processes.process_path.file_path = "*\\Users\\Default\\*" OR Processes.process_path.file_path = "*Recycle.bin*" OR Processes.process_path = "*\\Windows\\Media\\*" OR Processes.process_path = "\\Windows\\repair\\*" OR Processes.process_path = "*\\temp\\*" OR Processes.process_path = "*\\PerfLogs\\*" by Processes.parent_process_name Processes.parent_process Processes.process_path Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_process_file_path_filter`' how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. known_false_positives: Administrators may allow execution of specific binaries in non-standard paths. Filter as needed. references: - https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/ - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ - https://twitter.com/pr0xylife/status/1590394227758104576 tags: analytic_story: - Data Destruction - Double Zero Destructor - XMRig - Remcos - WhisperGate - Hermetic Wiper - Industroyer2 - DarkCrystal RAT - Brute Ratel C4 - AgentTesla - Qakbot - IcedID - Trickbot - Azorult - Prestige Ransomware - Chaos Ransomware - LockBit Ransomware automated_detection_testing: passed confidence: 50 context: - Source:Endpoint - Stage:Execution - Stage:Initial Access dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log impact: 70 kill_chain_phases: - Exploitation message: Suspicioues process $Processes.process_path.file_path$ running from suspicious location mitre_attack_id: - T1543 observable: - name: dest type: Endpoint role: - Victim - name: Processes.process_path.file_path type: File Name role: - Attacker product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud required_fields: - _time - Processes.process_name - Processes.process - Processes.parent_process_name - Processes.parent_process - Processes.process_path - Processes.dest - Processes.user risk_score: 35 security_domain: endpoint supported_tas: - Splunk_TA_microsoft_sysmon asset_type: Endpoint