Windows Console Execution from Unbacked Memory
Description
Identifies the creation of a Windows console host process where the creating thread's stack contains frames pointing outside any known executable image. This may be indicative of the use of a built-in Windows shell from an injected process.
Query · eql
sequence with maxspan=5m
[process where event.action == "start" and process.parent.executable != null and
process.parent.thread.Ext.call_stack_contains_unbacked == true and
(process.executable : "?:\\Windows\\Sys*\\conhost.exe" and process.args : "0xffffffff") and
process.parent.thread.Ext.call_stack_summary :
("ntdll.dll|kernelbase.dll|Unbacked",
"ntdll.dll|wow64.dll|wow64cpu.dll|wow64.dll|ntdll.dll|kernelbase.dll|Unbacked",
"ntdll.dll|wow64.dll|wow64cpu.dll|wow64.dll|ntdll.dll|kernelbase.dll|Unbacked|kernel32.dll|ntdll.dll") and
not (user.id == "S-1-5-18" and
process.parent.executable :
("?:\\ProgramData\\*.exe",
"?:\\Program Files\\*.exe",
"?:\\Program Files (x86)\\*.exe",
"?:\\Windows\\LTSvc\\LTSVC.exe",
"?:\\Windows\\System32\\msiexec.exe",
"C:\\Windows\\_ScriptingFramework\\Modul\\Engine.exe",
"C:\\Windows\\_ScriptingFramework\\Modul\\ScriptingFrameworkEngine.exe",
"C:\\Windows\\SysWOW64\\SmartDeploy\\ClientService.exe",
"I:\\RSA\\Microsoft Azure Recovery Services Agent\\bin\\cbengine.exe",
"C:\\Drivers\\Nord\\NordSec ThreatProtection\\nordsec-threatprotection-service.exe")) and
not (process.parent.executable : "?:\\Windows\\System32\\WindowsPowerShell\\*\\powershell.exe" and user.id : "S-1-5-18" and
process.code_signature.trusted == true) and
not (process.code_signature.subject_name : "ProVation Medical" and process.code_signature.trusted == true) and
not (process.parent.code_signature.subject_name in ("UiPath, Inc.", "QSR International Pty Ltd") and process.parent.code_signature.trusted == true) and
not process.parent.executable :
("?:\\Packages\\Plugins\\Microsoft.GuestConfiguration.ConfigurationforWindows\\*\\gc_service.exe",
"?:\\Windows\\System32\\wsmprovhost.exe",
"?:\\Program Files (x86)\\Wondershare\\*.exe",
"?:\\Windows\\System32\\drivers\\*.exe",
"?:\\Program Files*\\Cloudflare\\*.exe",
"?:\\Program Files (x86)\\Universal\\Universal.Server.exe",
"?:\\Program Files*\\Listary\\Listary.exe",
"?:\\Program Files*\\ExpressConnect\\ECDBWMService.exe",
"?:\\ProVation\\Utilities\\ProVation.DataExport\\ProVation.DataExport.exe",
"?:\\Windows\\System32\\WindowsPowerShell\\*\\powershell_ise.exe",
"?:\\WINDOWS\\_ScriptingFramework\\Modul\\Engine.exe",
"?:\\Program Files\\Citrix\\Telemetry Service\\TelemetryService.exe",
"?:\\ProVation\\Utilities\\Database Utilities\\ProVation.DataExport.exe",
"?:\\Program Files*\\UiPath\\Studio\\UiPath.Studio.Project.exe",
"?:\\Program Files*\\Microsoft System Center\\Operations Manager\\Server\\MonitoringHost.exe",
"?:\\Program Files (x86)\\Canfield Scientific Inc\\PortalService\\CanfieldRegister.exe",
"?:\\Program Files*\\Microsoft System Center\\Operations Manager\\Server\\MonitoringHost.exe",
"?:\\Drivers\\MITS_FATClient_SupportTool\\MITS_FATClient_SupportTool_admin.exe",
"?:\\Program Files*\\Microsoft Visual Studio\\*\\Community\\Common?\\IDE\\devenv.exe",
"?:\\Program Files\\ObserveIT\\WebsiteCat\\WebsiteCat.Manager.exe",
"?:\\Program Files\\Microsoft Azure Active Directory Connect\\AzureADConnect.exe",
"?:\\Program Files (x86)\\vMix\\vMix64.exe",
"?:\\Work\\HP DIAG TOOL\\ImageDiags.exe",
"C:\\Work\\ImageDiags.exe",
"?:\\Program Files (x86)\\Driver Support One\\DSOneWeb.exe",
"?:\\Program Files (x86)\\Team Shinkansen\\Hakchi2 CE\\hakchi.exe",
"?:\\Program Files (x86)\\HP DIAG TOOL\\ImageDiags.exe",
"?:\\ProVation\\Utilities\\Database Utilities\\ProVation.DataExport19c\\ProVation.DataExport.exe",
"?:\\Program Files\\WindowsApps\\*\\DCv2\\DCv2.exe",
"?:\\Users\\*\\Desktop\\HP DIAG TOOL\\ImageDiags.exe",
"?:\\ProVation\\Utilities\\Database Utilities\\ProVation.DataExport*\\ProVation.DataExport.exe",
"\\Device\\Mup\\*\\Release\\CorrespondanceDownload.vshost.exe",
"?:\\Users\\*\\AppData\\Local\\Programs\\UiPath\\Studio\\UiPath.Studio.Project.exe",
"D:\\*\\Exporter\\bin\\Debug\\Exporter.vshost.exe",
"C:\\Windows\\SysWOW64\\SmartDeploy\\ClientService.exe",
"C:\\Program Files\\QSR\\NVivo ??\\NVivo.exe",
"C:\\Program Files\\McCormick Systems\\McCormick Estimating\\MaintenanceUtility.exe",
"D:\\PROGRAMS\\UiPath\\Studio\\UiPath.Studio.Project.exe",
"C:\\Users\\*\\AppData\\Roaming\\GWP\\MSOffice-AddIns\\Deploy-MSOfficeAddIns.exe",
"C:\\Program Files\\Devolutions\\Remote Desktop Manager\\RemoteDesktopManager.exe",
"C:\\Program Files\\QSR\\NVivo 14\\NVivo.exe",
"C:\\Program Files (x86)\\Genetec SV Control Panel\\Control Panel\\SVControlPanel.exe",
"D:\\PROGRAMS\\UiPath\\Studio\\UiPath.Studio.Project.exe",
"C:\\Program Files (x86)\\Chocolatey GUI\\ChocolateyGui.exe",
"C:\\Program Files\\Royal TS V7\\RoyalTS.exe",
"C:\\Program Files\\QSR\\NVivo ??\\NVivo.exe",
"C:\\Program Files\\Password Safe and Repository*\\PSRServer.exe",
"C:\\Program Files\\WindowsApps\\Microsoft.GetHelp_*\\GetHelp.exe",
"C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_*\\DotNet\\ConfigurationRemotingServer.exe",
"C:\\Program Files (x86)\\CentraStage\\CagService.exe",
"D:\\Microsoft Azure\\Microsoft Azure Recovery Services Agent\\bin\\cbengine.exe",
"C:\\Program Files (x86)\\BMW\\ISPI\\ISVM\\IMIBNext\\Ediabas\\bin\\EbasServer.exe",
"C:\\Program Files\\ASUS\\ASUS VeriView\\ASUSEventClient.exe",
"C:\\Program Files (x86)\\Kovai Ltd\\BizTalk360\\Service\\BHMCollect.exe",
"C:\\Program Files\\Common Files\\eClinicalWorks\\plugin\\WinProjectE.exe",
"C:\\Program Files (x86)\\BizTalkHealthMonitor\\BHMCollect.exe",
"?:\\Program Files (x86)\\Welch Allyn\\Connex\\Server\\*\\DataBaseInstaller\\DatabaseInstaller.exe") and
not _arraysearch(process.parent.thread.Ext.call_stack, $entry,
$entry.callsite_trailing_bytes :
("c6460c01833d*e85ff0f95c00fb6c00fb6c0c6460c01488b559048895610488d65c85b5e5f415c415d415e415f",
"*48895610488d65c85b5e5f415c415d415e415f5dc30000001910090010c20c300b60*",
"*95c00fb6c0488b5588488956104883c4785b5e5f415c41*",
"c6460c01833d9c8c755e007406ff15a495755e85c00f95c00fb6c00fb6c0c6460c01488b559048895610488d65c85b5e5f415c415d415e415f5dc31910090010"))
] by process.parent.entity_id
[network where true] by process.entity_id