Elastic Defend high stable eql

Suspicious Remote Memory Allocation

Identifies attempts to allocate remote memory with RWX permissions, this behavior is often associated with remote process injection preparation.

View Source

Detection Logic

api where process.Ext.api.name == "VirtualAllocEx" and process.executable != null and 
  process.Ext.api.parameters.protection == "RWX" and process.Ext.api.parameters.size >= 10000 and 
  process.thread.Ext.call_stack_summary like "?*" and not user.id in ("S-1-5-19", "S-1-5-20") and
  process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
  not (process.executable : ("?:\\Program Files\\*.exe", "?:\\Program Files (x86)\\*.exe", "?:\\Windows\\*") and
       process.code_signature.trusted == true and not process.code_signature.subject_name like "Microsoft*") and
  not (process.executable : "?:\\Windows\\System32\\RPC\\OSD\\osdservice.exe" and user.id == "S-1-5-18" and
       process.code_signature.subject_name == "Microsoft Windows Hardware Compatibility Publisher") and
  not _arraysearch(process.thread.Ext.call_stack, $entry,
                   $entry.symbol_info : ("?:\\Program Files\\*.dll*", 
                                         "?:\\Program Files (x86)\\*.dll*", 
                                         "?:\\windows\\system32\\*\\tmmon*.dll*", 
                                         "?:\\Windows\\SysWOW64\\esensordbi.dll*", 
                                         "?:\\Windows\\System32\\esensordbi.dll*", 
                                         "?:\\Windows\\System32\\umppc*.dll*", 
                                         "?:\\Windows\\FireEye\\AppMonitorDll*.dll*", 
                                         "?:\\Windows\\apppatch\\AppPatch*\\exploitblocker.dll*", 
                                         "?:\\windows\\system32\\hmpalert.dll!*",
                                         "*ntdll.dll!NtCreateUserProcess*",
                                         "*\\kernelbase.dll+0x*",
                                         "?:\\windows\\system32\\wlidsvc.dll!SvchostPushServiceGlobals*",
                                         "?:\\windows\\system32\\appxdeploymentserver.dll!*",
                                         "?:\\windows\\system32\\webruntimemanager.dll!CreateMessagePortEventDispatcher*",
                                         "?:\\windows\\systemapps\\microsoft.aad.brokerplugin_*\\aad.core.dll!DllGetActivationFactory*",
                                         "?:\\windows\\system32\\driverstore\\filerepository\\iigd_dch.inf_amd64_*\\igd12um64icl.dll*")) and
  not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.protection_provenance like "Kernel*") and
  /* Cynet MemScanner, xSecuritas, Mcafee */
   not _arraysearch(process.thread.Ext.call_stack, $entry,
                    $entry.callsite_trailing_bytes in
                         ("48898424e80300004883bc24e803000000750eff94247e030000898424f0030000eb30488d8c2430010000ff94248e03000048898424e80300004883bc24e803",
                          "8bd885db751eff55c88945f8eb168d8592fdffff50ff55d08bd885db7506ff55c88945f856ff55bc85db0f847601000080bd82fcffff0074508b45fc05a00000",
                          "488b55a8c6420c01833d8bbeb25f007406ff1593c7b25f8945b4488bcce82c000000908b45b4488b55a8c6420c01488b55a8488b8d70ffffff48894a10488d65", 
                          "2048894538488b4d1048c1e103488b7d38488b7550f3a44c8b4d284d8b49484c8b45284d8b4040488b5528488b5220488b4d28488b8988000000ff95a0000000")) and
   not (process.name : "rundll32.exe" and process.parent.executable : "?:\\Users\\*\\AppData\\Local\\Temp\\SNXAC\\STAProxy.exe" and
        process.command_line : "*\\Users\\*\\AppData\\Local\\Temp\\snxac\\*\\sta.dll*") and 
   not (process.code_signature.trusted == true and 
        process.code_signature.subject_name in
              ("GEOVISION INC.", "COMPUTACION EN ACCION SA DE CV", "Crownalytics, LLC", "Johannes Schindelin", 
               "INCA Internet Co.,Ltd.", "Mark Straver", "Micro Systemation AB (publ)", "HardestCodesEst OU",
               "MUSARUBRA US LLC", "Fleischhacker GmbH & Co. KG Laboreinrichtungen Medizintechnik")) and
   not (process.executable : "?:\\Users\\*\\AppData\\Local\\Mozilla Firefox\\firefox.exe" and 
        process.code_signature.subject_name == "Mozilla Corporation" and process.code_signature.trusted == true) and
   not (process.executable : "?:\\Program Files (x86)\\Steam\\steamapps\\common\\*.exe" and process.code_signature.trusted == true) and 
   not (process.executable : "?:\\Program Files (x86)\\Microsoft\\EdgeUpdate\\MicrosoftEdgeUpdate.exe" and 
        process.parent.executable : ("?:\\Windows\\System32\\SecurityHealthSystray.exe", "?:\\Users\\*\\AppData\\Local\\Microsoft\\OneDrive\\*\\FileCoAuth.exe") and 
        process.Ext.api.summary : "VirtualAllocEx*microsoftedgeupdate.exe,*") and 
   not process.parent.executable :
               ("?:\\Program Files (x86)\\Embarcadero\\Studio\\*\\bin\\bds.exe",
                "?:\\Program Files\\Embarcadero\\Studio\\*\\bin\\bds.exe",
                "?:\\Program Files (x86)\\Microsoft Visual Studio\\*\\Professional\\Common?\\IDE\\devenv.exe") and
   not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == true and
                  $entry.subject_name in ("Microsoft Windows Hardware Compatibility Publisher",
                                          "Microsoft Windows Software Compatibility Publisher",
                                          "FastTrack Software ApS",  "FastTrack Software Aps", "Promon AS", "PC Matic, Inc")) and
   not process.thread.Ext.call_stack_final_user_module.hash.sha256 in ("b4f289b5bf0beb59e7ba8d00b45ffaa582114c22a959bb8912cd8b903748f91b",
                                                                       "b950277c03155ffef055fd2fb6c9afe2022ac6402f8e04ece92f34bedf5bc194",
                                                                       "289ccce952e8a5ad4eae60fbfcfc239a2c6a45386655466ce45f77c9422533da",
                                                                       "8d80ea047a89300017544fc28a402c6f45b7369413c51c7b352af69db503d9bb",
                                                                       "b88d6fdb2641981675e1066f0767a8f263c5c4dcc5fccddbb948cdbe4165aef4",
                                                                       "90db33e5c6f2d0e3f60de07821413a24d31ceec26c83b447ff3a3607ebc67079",
                                                                       "73395b6c3fa9fa73e8e3665f108b3a92c564da9c1b9ce7834832adbb5e658a87",
                                                                       "4a81edc822ee7e6fb1ca1813f4c917f11b4366d33fd55c294d6509b4d4c0d80e",
                                                                       "d355b62cc7dc5b8f3ee5e95a8ddddc818f6f84c5a16799d78b1cb3d786e2bb80",
                                                                       "07d6c3a19a8e3e243e9545a41dd30a9ee1e9ad79cdd6d446c229d689e5ab574a") and
   not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry,
                    $entry.trusted == true and not $entry.subject_name in ("Microsoft Corporation", "Microsoft Windows"))

Field Validations

Loading…

Comments (0)

Loading comments...