Image Hollow from Unusual Stack


Description

Identifies attempt to modify the content of a loaded module and from a suspicious call stack. This may indicate an attempt to inject code using module stomping or DLL hollowing via overwriting the content of a legit DLL with malicious code.

Query · eql

api where process.Ext.api.behaviors == "hollow_image" and
  process.Ext.api.name == "VirtualProtect" and
  process.Ext.api.parameters.size >= 10000 and process.executable != null and
  process.thread.Ext.call_stack_summary in
                     ("ntdll.dll|kernelbase.dll|Unbacked",
                      "ntdll.dll|kernelbase.dll|kernel32.dll|Unbacked",
                      "ntdll.dll|wow64.dll|wow64cpu.dll|wow64.dll|ntdll.dll|kernelbase.dll|Unbacked",
                      "ntdll.dll|wow64.dll|wow64cpu.dll|wow64.dll|ntdll.dll|kernelbase.dll|Unbacked|kernel32.dll|ntdll.dll") and
  process.Ext.api.metadata.target_address_path like "c:\\windows\\sys?????\\*.dll" and
  process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
  not _arraysearch(process.thread.Ext.call_stack, $entry, 
                   $entry.protection_provenance like ("Kernel*", "tcaddin.dll", "clr.dll", "appvisvsubsystems64.dll", 
                                                  "appvisvsubsystems.dll", "softmon.exe|*", "appventsubsystems32.dll", 
                                                  "appventsubsystems64.dll", "appventsubsystems.dll")) and
  not (process.Ext.api.summary : ("*qipcap64.dll*", "*redemption64*", "*eowp.22.1.94.0.exe*", "*conemuhk64.dll*", "*xalan-c_1_10.dll*", "* av.dll*",
                                 "*crpe32.dll*", "*_*.dll*", "*-*.dll*", "*sqlite?.dll*", "*appprofiler.x64.dll*", "*appprofiler.x86.dll*", "*qmgr.dll*", "*cxll*.llx*", "*.exe*") and
                                  not process.Ext.api.summary : "*ws2_32*") and
  not (process.parent.executable : "?:\\Program Files (x86)\\think-cell\\tcasr.exe" and 
       process.executable : "?:\\Program Files\\Microsoft Office\\root\\Office*\\EXCEL.EXE") and
  not (process.code_signature.subject_name : ("Code Systems Corporation", "Essential Objects, Inc.", "JAM Software GmbH",
                                              "IMSI Design, LLC", "Nuance Communications, Inc.", "Rocket Software, Inc.", 
                                              "Tracker Software Products (Canada) Ltd", "Sage Software, Inc.", "Azul Systems, Inc.",
                                              "Essential Objects, Inc.") and
       process.code_signature.trusted == true) and
  not (process.parent.executable : ("?:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe", "?:\\Program Files\\Google\\Update\\GoogleUpdate.exe") and
       process.executable : ("?:\\Program Files (x86)\\Google\\Update\\*\\GoogleCrashHandler*.exe", "?:\\Program Files\\Google\\Update\\*\\GoogleCrashHandler*.exe")) and
  not process.executable :
               ("?:\\Program Files\\*.exe",
                "?:\\Program Files (x86)\\*.exe",
                "?:\\Windows\\System32\\inetsrv\\w3wp.exe", 
                "?:\\Windows\\SysWOW64\\inetsrv\\w3wp.exe", 
                "?:\\Windows\\SystemApps\\*.exe", 
                "?:\\Windows\\System32\\taskhostw.exe") and
  not (process.executable : "?:\\Windows\\Sys*\\msiexec.exe" and process.Ext.api.summary : "*msi*.tmp*") and
  not (process.executable : "?:\\Windows\\Sys*\\rundll32.exe" and process.command_line : ("*--no-sandbox*", "*--eoim*")) and
  not (process.executable : "?:\\Windows\\System32\\backgroundTaskHost.exe" and
       process.parent.executable : "?:\\Windows\\System32\\svchost.exe") and
  not process.parent.executable : ("?:\\Program Files (x86)\\Steam\\steam.exe", "?:\\Program Files\\Steam\\steam.exe") and
  not (process.Ext.api.metadata.target_address_name : "cxll27*.llx" and process.parent.executable : "C:\\Program Files (x86)\\Citrix\\HDX\\bin\\WfShell.exe") and
  not (process.Ext.api.metadata.target_address_name == "libcapki.dll" and process.parent.executable : "C:\\Program Files (x86)\\CA\\DSM\\Bin\\*.exe") and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 in ("2ef1f7e839e332d97e32ee0213c92d0e74536fb3af04b6df1d335e2f101f968e",
   "a20a14118c2f06a1cc502095a1f18b3cb34ad75f1684f7ec26e24a68d4e3114c", "da502d1a77883ab56d110889237ce7f18527a1d78e85078f40d269966059e267",
   "2a2f9dc5f88e4596ade6a57ec2baa8586dbade44e6df9ecb32035cfd1d8bd85d", "c7d833a8fdfac8a79f9f861af7f6f476bb7b36c71c5fa60e668728008b16a43e") and
  not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == true)
Raw source Image Hollow from Unusual Stack · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Identifies attempt to modify the content of a loaded module and from a suspicious call stack. This may indicate an
attempt to inject code using module stomping or DLL hollowing via overwriting the content of a legit DLL with malicious
code.
"""
id = "446e61bf-8370-45df-88ab-7b213ee653db"
license = "Elastic License v2"
name = "Image Hollow from Unusual Stack"
os_list = ["windows"]
version = "1.0.22"

query = '''
api where process.Ext.api.behaviors == "hollow_image" and
  process.Ext.api.name == "VirtualProtect" and
  process.Ext.api.parameters.size >= 10000 and process.executable != null and
  process.thread.Ext.call_stack_summary in
                     ("ntdll.dll|kernelbase.dll|Unbacked",
                      "ntdll.dll|kernelbase.dll|kernel32.dll|Unbacked",
                      "ntdll.dll|wow64.dll|wow64cpu.dll|wow64.dll|ntdll.dll|kernelbase.dll|Unbacked",
                      "ntdll.dll|wow64.dll|wow64cpu.dll|wow64.dll|ntdll.dll|kernelbase.dll|Unbacked|kernel32.dll|ntdll.dll") and
  process.Ext.api.metadata.target_address_path like "c:\\windows\\sys?????\\*.dll" and
  process.thread.Ext.call_stack_final_user_module.hash.sha256 != null and
  not _arraysearch(process.thread.Ext.call_stack, $entry, 
                   $entry.protection_provenance like ("Kernel*", "tcaddin.dll", "clr.dll", "appvisvsubsystems64.dll", 
                                                  "appvisvsubsystems.dll", "softmon.exe|*", "appventsubsystems32.dll", 
                                                  "appventsubsystems64.dll", "appventsubsystems.dll")) and
  not (process.Ext.api.summary : ("*qipcap64.dll*", "*redemption64*", "*eowp.22.1.94.0.exe*", "*conemuhk64.dll*", "*xalan-c_1_10.dll*", "* av.dll*",
                                 "*crpe32.dll*", "*_*.dll*", "*-*.dll*", "*sqlite?.dll*", "*appprofiler.x64.dll*", "*appprofiler.x86.dll*", "*qmgr.dll*", "*cxll*.llx*", "*.exe*") and
                                  not process.Ext.api.summary : "*ws2_32*") and
  not (process.parent.executable : "?:\\Program Files (x86)\\think-cell\\tcasr.exe" and 
       process.executable : "?:\\Program Files\\Microsoft Office\\root\\Office*\\EXCEL.EXE") and
  not (process.code_signature.subject_name : ("Code Systems Corporation", "Essential Objects, Inc.", "JAM Software GmbH",
                                              "IMSI Design, LLC", "Nuance Communications, Inc.", "Rocket Software, Inc.", 
                                              "Tracker Software Products (Canada) Ltd", "Sage Software, Inc.", "Azul Systems, Inc.",
                                              "Essential Objects, Inc.") and
       process.code_signature.trusted == true) and
  not (process.parent.executable : ("?:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe", "?:\\Program Files\\Google\\Update\\GoogleUpdate.exe") and
       process.executable : ("?:\\Program Files (x86)\\Google\\Update\\*\\GoogleCrashHandler*.exe", "?:\\Program Files\\Google\\Update\\*\\GoogleCrashHandler*.exe")) and
  not process.executable :
               ("?:\\Program Files\\*.exe",
                "?:\\Program Files (x86)\\*.exe",
                "?:\\Windows\\System32\\inetsrv\\w3wp.exe", 
                "?:\\Windows\\SysWOW64\\inetsrv\\w3wp.exe", 
                "?:\\Windows\\SystemApps\\*.exe", 
                "?:\\Windows\\System32\\taskhostw.exe") and
  not (process.executable : "?:\\Windows\\Sys*\\msiexec.exe" and process.Ext.api.summary : "*msi*.tmp*") and
  not (process.executable : "?:\\Windows\\Sys*\\rundll32.exe" and process.command_line : ("*--no-sandbox*", "*--eoim*")) and
  not (process.executable : "?:\\Windows\\System32\\backgroundTaskHost.exe" and
       process.parent.executable : "?:\\Windows\\System32\\svchost.exe") and
  not process.parent.executable : ("?:\\Program Files (x86)\\Steam\\steam.exe", "?:\\Program Files\\Steam\\steam.exe") and
  not (process.Ext.api.metadata.target_address_name : "cxll27*.llx" and process.parent.executable : "C:\\Program Files (x86)\\Citrix\\HDX\\bin\\WfShell.exe") and
  not (process.Ext.api.metadata.target_address_name == "libcapki.dll" and process.parent.executable : "C:\\Program Files (x86)\\CA\\DSM\\Bin\\*.exe") and
  not process.thread.Ext.call_stack_final_user_module.hash.sha256 in ("2ef1f7e839e332d97e32ee0213c92d0e74536fb3af04b6df1d335e2f101f968e",
   "a20a14118c2f06a1cc502095a1f18b3cb34ad75f1684f7ec26e24a68d4e3114c", "da502d1a77883ab56d110889237ce7f18527a1d78e85078f40d269966059e267",
   "2a2f9dc5f88e4596ade6a57ec2baa8586dbade44e6df9ecb32035cfd1d8bd85d", "c7d833a8fdfac8a79f9f861af7f6f476bb7b36c71c5fa60e668728008b16a43e") and
  not _arraysearch(process.thread.Ext.call_stack_final_user_module.code_signature, $entry, $entry.trusted == true)
'''

min_endpoint_version = "8.10.0"
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1055"
name = "Process Injection"
reference = "https://attack.mitre.org/techniques/T1055/"


[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"

[internal]
min_endpoint_version = "8.10.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.