Registry or File Modification from Suspicious Memory
Description
Identifies the modification of file or registry to set persistence or evade defense and from a call stack pointing to an unbacked memory region or Microsoft Visual Basics DLLs. Adversaries may use this technique to maintain persistence or evade defense from an injected process.
Query · eql
any where event.category in ("registry", "file") and event.action != "deletion" and
file.name != null and registry.data.strings != null and
process.thread.Ext.call_stack_summary like ("*|vbe?.dll*", "*kernelbase.dll|Unbacked*") and
(
(registry.data.strings != null and
registry.path :
("H*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\*",
"H*\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\*",
"H*\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run\\*",
"H*\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run\\*",
"H*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Runonce\\*",
"HKEY_USERS\\*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load",
"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
"HKEY_USERS\\*\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell",
"HKEY_USERS\\*\\Environment\\UserInitMprLogonScript",
"HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Userinit",
"HKEY_USERS\\*\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\Shell",
"HKEY_USERS\\*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\Scripts\\Logoff\\Script",
"HKEY_USERS\\*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\Scripts\\Logon\\Script",
"HKEY_USERS\\*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\Scripts\\Shutdown\\Script",
"HKEY_USERS\\*\\SOFTWARE\\Policies\\Microsoft\\Windows\\System\\Scripts\\Startup\\Script",
"HKEY_USERS\\*\\SOFTWARE\\Microsoft\\Ctf\\LangBarAddin\\*\\FilePath",
"HKEY_USERS\\*\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\*\\Exec",
"HKEY_USERS\\*\\SOFTWARE\\Microsoft\\Command Processor\\Autorun",
"HKEY_USERS\\*\\Environment\\UserInitMprLogonScript",
"HKEY_USERS\\*Classes\\*\\InprocServer32\\*",
"HKEY_USERS\\*Classes\\*\\DelegateExecute\\*",
"HKEY_USERS\\*Classes\\*\\TreatAs\\*",
"HKEY_USERS\\*Classes\\CLSID\\*\\ScriptletURL\\*",
"HKLM\\SYSTEM\\*ControlSet*\\Services\\*\\Parameters\\ServiceDll",
"HKLM\\SYSTEM\\ControlSet*\\Services\\*\\ImagePath",
"HK*\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
"HK*\\S-1-5-21-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
"HK*\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\AccessVBOM",
"HK*\\S-1-12-1-*\\SOFTWARE\\Microsoft\\Office\\*\\Security\\VbaWarnings",
"HKEY_USERS\\*\\Software\\Microsoft\\Windows Script\\Settings\\AmsiEnable",
"HK*\\*\\Software\\Microsoft\\Windows Script\\Settings\\AmsiEnable",
"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\ConsentPromptBehaviorAdmin",
"HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA")) or
(file.name != null and file.path : "?:\\*\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\*" and
not file.name : "desktop.ini")
) and
not (process.code_signature.trusted == true and registry.value : "com.squirrel.*" and
registry.data.strings : "*--process-start-args*" and
registry.path : "H*\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\*") and
not (process.executable : ("?:\\Program Files\\*", "?:\\Program Files (x86)\\*") and
process.code_signature.trusted == true and process.thread.Ext.call_stack_summary like "*|mscorlib.ni.dll|*") and
not process.thread.Ext.call_stack_summary like "*Unbacked|clr.dll|*" and
not (process.code_signature.trusted == true and
process.code_signature.subject_name : ("Autodesk, Inc.", "SimpleHelp Ltd", "Kaspersky Lab*", "JetBrains s.r.o.",
"IDrive, Inc.", "RingCentral, Inc.", "Plarium Global LTD", "Sanford, L.P.",
"CutCom Software Inc.", "Bluestack Systems, Inc")) and
/* Third party signed software from program files */
not (process.code_signature.trusted == true and
not process.code_signature.subject_name like "Microsoft*" and
process.executable : ("?:\\Program Files\\*.exe", "?:\\Program Files (x86)\\*.exe")) and
not process.executable :
("?:\\Program Files\\OpenVPN Connect\\OpenVPNConnect.exe",
"?:\\Program Files (x86)\\OpenVPN Connect\\OpenVPNConnect.exe",
"?:\\Program Files\\DYMO\\DYMO Label Software\\DYMO.DLS.Printing.Host.exe",
"?:\\Program Files (x86)\\DYMO\\DYMO Label Software\\DYMO.DLS.Printing.Host.exe",
"?:\\Program Files\\Microsoft Visual Studio\\Installer.*\\setup.exe",
"?:\\Program Files (x86)\\Microsoft Visual Studio\\Installer.*\\setup.exe")