Potential LogonUser API Hooking
Description
Identifies attempts to hook LogonUser API via memory modification. This may indicate an attempt to steal credentials passed for authentication verification via this API.
Query · eql
api where process.Ext.api.name in ("WriteProcessMemory", "VirtualProtect") and
process.Ext.api.metadata.target_address_name like "advapi32.dll!LogonUser*" and process.executable != null and
not process.thread.Ext.call_stack_final_user_module.name in ("Kernel", "Unknown", "Undetermined") and
not process.thread.Ext.call_stack_final_user_module.path in ("c:\\windows\\syswow64\\werfault.exe", "c:\\windows\\system32\\werfault.exe") and
not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == true or $entry.status like "errorCode_endpoint*") and
process.thread.Ext.call_stack_final_user_module.hash.sha256 != "fdfc853b183d682c912e6487a64dbaea98f8d09207a55d0a512e550c988d6273" and
not _arraysearch(process.thread.Ext.call_stack, $entry, $entry.symbol_info like "c:\\windows\\system32\\ntdll.dll!LdrLoadDll*") and
not process.thread.Ext.call_stack_final_user_module.path :
("?:\\program files\\avg\\antivirus\\aswhook.dll",
"?:\\program files\\avg\\antivirus\\x86\\aswhook.dll",
"?:\\program files\\avast software\\avast\\aswhook.dll",
"?:\\program files\\avast software\\avast\\x86\\aswhook.dll",
"?:\\windows\\assembly\\nativeimages_*\\microsoft.powershell.commands.management.ni.dll") and
not process.executable : ("C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe",
"C:\\Program Files (x86)\\Common Files\\Adobe\\Adobe Desktop Common\\IPCBox\\AdobeIPCBroker.exe",
"C:\\Program Files\\Avast Software\\Browser\\Application\\AvastBrowserProtect.exe")