mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
72 lines
2.7 KiB
YAML
72 lines
2.7 KiB
YAML
name: Windows Unsigned DLL Side-Loading
|
|
id: 5a83ce44-8e0f-4786-a775-8249a525c879
|
|
version: 2
|
|
date: '2024-05-31'
|
|
author: Teoderick Contreras, Splunk
|
|
status: production
|
|
type: Anomaly
|
|
data_source:
|
|
- Sysmon EventID 7
|
|
description: The following analytic detects the creation of potentially malicious
|
|
unsigned DLLs in the c:\windows\system32 or c:\windows\syswow64 folders. It leverages
|
|
Sysmon EventCode 7 logs to identify unsigned DLLs with unavailable signatures loaded
|
|
in these critical directories. This activity is significant as it may indicate a
|
|
DLL hijacking attempt, a technique used by attackers to gain unauthorized access
|
|
and execute malicious code. If confirmed malicious, this could lead to privilege
|
|
escalation, allowing the attacker to gain elevated privileges and further compromise
|
|
the target system.
|
|
search: '`sysmon` EventCode=7 Signed=false OriginalFileName = "-" SignatureStatus="unavailable"
|
|
ImageLoaded IN ("*:\\windows\\system32\\*", "*:\\windows\\syswow64\\*") | stats
|
|
count min(_time) as firstTime max(_time) as lastTime by Image ImageLoaded Signed
|
|
SignatureStatus OriginalFileName process_name dest EventCode ProcessId Hashes IMPHASH
|
|
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_unsigned_dll_side_loading_filter`'
|
|
how_to_implement: To successfully implement this search, you need to be ingesting
|
|
logs with the process name and imageloaded executions from your endpoints. If you
|
|
are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
|
|
known_false_positives: It is possible some Administrative utilities will load dismcore.dll
|
|
outside of normal system paths, filter as needed.
|
|
references:
|
|
- https://asec.ahnlab.com/en/17692/
|
|
- https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/warzone#:~:text=Warzone%20RAT%20(AKA%20Ave%20Maria)%20is%20a%20remote%20access%20trojan,is%20as%20an%20information%20stealer.
|
|
tags:
|
|
analytic_story:
|
|
- Warzone RAT
|
|
- NjRAT
|
|
asset_type: Endpoint
|
|
confidence: 70
|
|
impact: 70
|
|
message: An unsigned dll module was loaded on $dest$
|
|
mitre_attack_id:
|
|
- T1574.002
|
|
observable:
|
|
- name: dest
|
|
type: Endpoint
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
risk_score: 49
|
|
required_fields:
|
|
- _time
|
|
- Image
|
|
- ImageLoaded
|
|
- Signed
|
|
- SignatureStatus
|
|
- OriginalFileName
|
|
- process_name
|
|
- dest
|
|
- EventCode
|
|
- ProcessId
|
|
- Hashes
|
|
- IMPHASH
|
|
security_domain: endpoint
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data:
|
|
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/warzone_rat/unsigned_dll_loaded/loaded_unsigned_dll.log
|
|
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
sourcetype: xmlwineventlog
|