[ << ALL_FEED ]

Missed the moment a phishing attachment was launched again?

More in General

Missed the moment a phishing attachment was launched again? 📩

So what? The accountant is sure it was an “invoice” from a trusted bank. It’s time to teach SIEM systems to warn you about anomalies related to the launch of malicious email attachments!

We’re sharing a few ideas for correlation rules with you. This is part one. We’ll publish more soon 😉

1️⃣ Attackers may abuse double extensions in file names as a means of masking the true file type.

Such files are often used during phishing campaigns. It is recommended to monitor process launch events (Windows 4688, Sysmon 1) in which the process name ends with a double extension. In such events, popular harmless file formats are listed first:


.doc, .docx, .docm, .dot, .htm, .html, .odt, .pdf, .rtf, .txt, .xml, .csv, .xls, .xlsx, .xlsm, .zip, .zipx, .rar, .jar, .tar, .tar-gz, .tgz, .gz, .gzip, .7z, .pps, .ppsx, .ppt, .pptm, .pptx, .jpg, .jpeg, .gif, .png, .gif, .bmp, .raw, .tiff, .psd, .heif, .mp4, .mov, .wmv, .avi, .flv, .swf, .mkv
Code language: plaintext (plaintext)

And then — the executable file extension (.exe, .scr, .com), for example: Invoice_465937.doc.exe.

Example regex filter:

\.(doc|docx|docm|dot|htm|html|odt|pdf|rtf|txt|xml|csv|xls|xlsx|xlsm|zip|zipx|rar|jar|tar|tar-gz|tgz|gz|gzip|7z|pps|ppsx|ppt|pptm|pptx|jpg|jpeg|gif|png|gif|bmp|raw|tiff|psd|heif|mp4|mov|wmv|avi|flv|swf|mkv)\.(exe|scr|com)$
Code language: plaintext (plaintext)

2️⃣ Suspicious outbound connections from Microsoft Office applications can be detected based on Windows 5156 or Sysmon 3 events with destination port 445, from the following process names:


"winword.exe", "excel.exe", "powerpnt.exe", "visio.exe", "mspub.exe", "eqnedt32.exe", "outlook.exe"
Code language: plaintext (plaintext)

3️⃣ It is useful to pay attention to a user opening Microsoft Office documents with a macro, as well as to monitor the combination of process launch events for Microsoft Office applications (Windows 4688, Sysmon 1; processes: "winword.exe", "excel.exe", "powerpnt.exe", "msaccess.exe", "onenote.exe", "outlook.exe", "visio.exe", "winproj.exe").

And the loading of the VBE7 library by this process (Sysmon 7; ImageLoaded = VBE7.DLL).

4️⃣ Attackers may send a malicious document via a messenger, so it is recommended to detect process launches from a messenger parent process based on Windows 4688, Sysmon 1 events with the following ParentProcessName values:


"skype.exe", "telegram.exe","whatsapp.exe", "teams.exe", "lync.exe"
 Code language: plaintext (plaintext)

With different values in the ParentProcessName and NewProcessName fields.

5️⃣ Suspicious process launch sequences by a Microsoft Office application can be detected based on *.exe process launch events Windows 4688 Sysmon 1 with parent processes ParentProcessName (“winword.exe”, “excel.exe”, “powerpnt.exe”, “visio.exe”, “mspub.exe”, “eqnedt32.exe”, “outlook.exe”, “acrord32.exe”) with different values in the ParentProcessName and NewProcessName fields.

Exceptions for NewProcessName:


"winword.exe", "excel.exe", "powerpnt.exe", "eqnedt32.exe", "outlook.exe", "msosync.exe", "chrome.exe", "firefox.exe", "msedge.exe", "launcher.exe", "browser.exe", "acrord32.exe", "acrobat.exe", "rdrcef.exe", "adobearm.exe", "splwow64.exe", "visio.exe".
Code language: plaintext (plaintext)

6️⃣ We recommend detecting the creation of executable files by office programs:

• process creation events (Windows 4688, Sysmon 1);

• with Image names: "winword.exe", "excel.exe", "powerpnt.exe", "visio.exe", "mspub.exe", "eqnedt32.exe", "outlook.exe", "msaccess.exe";

• TargetFilename extension:


.exe, .bat, .com, .cmd, .dll, .cpl, .msi, .sys, .scr, .ps1, .hta
Code language: plaintext (plaintext)

7️⃣ An office program loads the DLL library of the Internet Explorer COM object (ieproxy.dll):

• Sysmon 7 events;

• with Image names: “winword.exe”, “excel.exe”, “powerpnt.exe”, “visio.exe”, “mspub.exe”, “eqnedt32.exe”, “outlook.exe”, “msaccess.exe”.

• the value “ieproxy.dll” in the ImageLoaded field.

 

#tips #siem #detect
@ptescalator

More from global_author

More from global_author

More in General