Detection Logic
//https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/G2JS/production/hxioc/SUSPICIOUS EXECUTION OF COLORCPL.EXE (METHODOLOGY).ioc
//This IOC detects suspicious parent and child processes relation with colorcpl.exe.
let lolbins = dynamic(["At.exe", "Atbroker.exe", "Bash.exe", "Bitsadmin.exe", "CertReq.exe", "Certutil.exe", "Cmd.exe", "Cmdkey.exe", "Cmstp.exe", "Control.exe", "Csc.exe", "Cscript.exe", "Desktopimgdownldr.exe", "Dfsvc.exe", "Diantz.exe", "Diskshadow.exe", "Dnscmd.exe", "Esentutl.exe", "Eventvwr.exe", "Expand.exe", "Extexport.exe", "Extrac32.exe", "Findstr.exe", "Forfiles.exe", "Ftp.exe", "GfxDownloadWrapper.exe", "Gpscript.exe", "Hh.exe", "Ie4uinit.exe", "Ieexec.exe", "Ilasm.exe", "Infdefaultinstall.exe", "Installutil.exe", "Jsc.exe", "Makecab.exe", "Mavinject.exe", "Microsoft.Workflow.Compiler.exe", "Mmc.exe", "MpCmdRun.exe", "Msbuild.exe", "Msconfig.exe", "Msdt.exe", "Mshta.exe", "Msiexec.exe", "Netsh.exe", "Nslookup.exe", "Odbcconf.exe", "Pcalua.exe", "Pcwrun.exe", "Pktmon.exe", "Powershell.exe", "Presentationhost.exe", "Print.exe", "Psr.exe", "Pwsh.exe", "Rasautou.exe", "Reg.exe", "Regasm.exe", "Regedit.exe", "Regini.exe", "Register-cimprovider.exe", "Regsvcs.exe", "Regsvr32.exe", "Replace.exe", "Rpcping.exe", "Rundll32.exe", "Runonce.exe", "Runscripthelper.exe", "Sc.exe", "Schtasks.exe", "Scriptrunner.exe", "SyncAppvPublishingServer.exe", "Ttdinject.exe", "Tttracer.exe", "vbc.exe", "Verclsid.exe", "Wab.exe", "Wmic.exe", "Wscript.exe", "Wsreset.exe", "Xwizard.exe", "AgentExecutor.exe", "Appvlp.exe", "Bginfo.exe", "Cdb.exe", "csi.exe", "Devtoolslauncher.exe", "dnx.exe", "Dotnet.exe", "Dxcap.exe", "Mftrace.exe", "Msdeploy.exe", "msxsl.exe", "ntdsutil.exe", "rcsi.exe", "Sqldumper.exe", "Sqlps.exe", "SQLToolsPS.exe", "Squirrel.exe", "Svchost.exe", "te.exe", "Tracker.exe", "Update.exe", "Wsl.exe", "ipconfig.exe", "whoami.exe", "net.exe", "net1.exe"]);
let var1=DeviceProcessEvents
| where FileName endswith ".exe" and FolderPath has_any (@"\Windows\System32\colorcpl\",@"\Windows\SysWOW64\colorcpl\")
| where InitiatingProcessFileName in ("cscript.exe","wscript.exe","mshta.exe","winword.exe","excel.exe","outlook.exe","powerpnt.exe");
let var2=DeviceProcessEvents
| where InitiatingProcessFileName endswith ".exe" and InitiatingProcessFolderPath has_any (@"\Windows\System32\colorcpl\",@"\Windows\SysWOW64\colorcpl\") and FileName in~(lolbins);
union var1,var2 Field Validations
Loading…
Comments (0)
Loading comments...