SigmaHQ/rules/windows/process_creation/win_apt_bluemashroom.yml

28 lines
812 B
YAML
Raw Normal View History

2019-10-02 12:02:07 +00:00
title: BlueMashroom DLL Load
2019-11-12 22:12:27 +00:00
id: bd70d3f8-e60e-4d25-89f0-0b5a9cff20e0
2019-10-02 11:57:14 +00:00
status: experimental
2019-10-02 12:02:07 +00:00
description: Detects a suspicious DLL loading from AppData Local path as described in BlueMashroom report
2019-10-02 11:57:14 +00:00
references:
2019-11-12 22:12:27 +00:00
- https://www.virusbulletin.com/conference/vb2019/abstracts/apt-cases-exploiting-vulnerabilities-region-specific-software
2019-10-02 11:57:14 +00:00
tags:
- attack.defense_evasion
- attack.t1117 # an old one
2020-06-16 20:46:08 +00:00
- attack.t1218.010
2019-10-02 11:57:14 +00:00
author: Florian Roth
date: 2019/10/02
logsource:
category: process_creation
product: windows
detection:
selection:
2020-11-28 08:48:30 +00:00
- CommandLine|contains|all:
- '\regsvr32'
- '\AppData\Local\'
- CommandLine|contains|all:
- '\AppData\Local\'
- ',DllEntry'
2019-10-02 11:57:14 +00:00
condition: selection
falsepositives:
- Unlikely
level: critical