Shellcode Execution from Low Reputation Module


Description

Identifies attempt to allocate or execute Shellcode from a module with low or unknown reputation.

Query · eql

sequence by process.entity_id with maxspan=1m
[library where
  not dll.code_signature.status == "trusted" and
  not dll.code_signature.status == "errorCode_endpoint: Failure in an external software component" and
  (dll.Ext.relative_file_creation_time <= 3600 or dll.Ext.relative_file_name_modify_time <= 3600) and 
  not dll.path : ("?:\\windows\\assembly\\nativeimages_*", "c:\\windows\\ccmcache\\*") and
  not (dll.path : "?:\\Windows\\Installer\\*.tmp" and process.name : "msiexec.exe") and
  not dll.hash.sha256 in
              ("29ae6f149e581f8dbdc01eed2d5d20b82b597c4b4c7e102cab6d012b168df4d8",
               "e2705efc246b6cd16ec560122d595394bb01de90db963d409c33f5330a871a93",
               "c4fe4ea78a4134349dfa71f4059b6233a8d1bb4b7592b66da89619726131bd2d",
               "2d81ba21fe9a567dd0fc283afaee95320579c2db163499593bfdc9032b29b925",
               "6ee97fdac52b4a673e9289124be4ce86a6d33e460aa71577848880f6f2ea8b99",
               "3b9aef3265246eac39e4bbacba2b057d5fcd1705c32679254e9ab94d267cb0ac",
               "43af7fe8fc892c3c013f2b980b5295d2e13b0c2e1d1123841ede8a62b94f08a4",
               "5acb0c408b3309a313623d05868ca7359dc17cf113461ffa0522f5df10963644",
               "9c973a0aca4147970c3e714a8750fbceda27f6d96fdfb04c8f5f24f66abde6aa",
               "c16f23e42ecdfe6561d2d9c9ce746630252f1ad15fa670d60ef268c1a7819c10",
               "10f5e4152ad9072116c6925defb54ccd56993b33bfad0c80b43cc3ea6daca812",
               "e5c81555bcc87dc59574f546f19af7d9a0ca564b254178148112d79201d2bf9c",
               "0d5d73d3bea132f98be91f918d13043791decb419a81d9e755979315a7cf0502",
               "beea6a901336753d2a9b8802a8cfa88da2619bebf9fafbef6bbab07b0d4eddcb",
               "dfde40ca8128e6cc3b046ede410be4734bc1ba552ce546e62bac40ad7d69dec0",
               "ba877ea99e9ebd794266529dc0228d279219516349fbbefc0bdd5dfd514eb52f",
               "beea6a901336753d2a9b8802a8cfa88da2619bebf9fafbef6bbab07b0d4eddcb",
               "3f2fb2aa90ca14fe598bd2ec32e2fc6818f5784fa0cd69160939b7394a4f8bdd",
               "15efeb9a8ab4d7553ce58e825c7a7ac5852a5a217722d92bdec17a890c2e006d",
               "efd601882adb9cba4adbce6770be1ff62302f3f10321657c527a9c647faccd15",
               "c233341d1b6bee8a61c8748e956d8f9ec6c4c1bb93de0322639da46c8d9bbf92",
               "de7585c96725bbe66e11c3c80aebb66cd61b901d6acf983b63c29e64e0cfbc9c",
               "4c28bcbbbd54e0c7e43cb1cb9980918668ca6cab379ad114e9d1d4640b5ef154",
               "19f75446ac56ee7bf3efe1cc25383fcab91a557f9b6257b39e496ec4a6ff8b2e",
               "e2b761094a6f6300da32e861e8f42c359b22a0cf1d62ff3a2721882aa4d1c2c6",
               "f0997f96bc59a9ff7d7fb8905b79996a179bfaad39a6113c9edf00135a96c561",
               "ef14a3b57cd57f97fea9fcbf81b3350d0f11785ecc27e37085110f380ddcb17d",
               "db3477572af5b5f353e723db1e7e8de9b743a120a145c3c26851e969ac34044d",
               "5655e005145c8a0bd1648bae17d456f14321d054240486dff349253c2c8da087",
               "d57cdf9fe51debc65441be155eddb663cebfaec1c0c91161234dd3398ca71b76",
               "22ee08ed8c02358f994b5deba0940735b161f9a73ad60e4e57d10b9e1988ec83",
               "88f0452c2ac66146139b87e60e9bb8a8b6a6566cbb9040e5e8ee1774e12f35ba",
               "4379d68dde8fb1f022a870947d0524c0ed8a7b37bcfc49772a4d0a4e04158b7b",
               "f7d7680d544e9e8da9b95c8905e5d2ca5adc2a3e700c2e1aa1f99287da0d184c",
               "6f49e3558970540edfb187c59d32f3a27eecc6a48d87b49ad72c19495355f1db",
               "bce30810240512dde3f6513b3734ae0f6b98c35ac5465e5e12262db8a086e37e",
               "32394db9c0677d31efd0d684e969c6fab55fa1c47114c980a9e3f39ff85f2e58",
               "fb6ec0f7104fec7d0963c53754e84dcb13d6d94c0d19762a2f161503ea5e3580",
               "6a1081e60b6c3e22cf58bb21267230c1dd61bb741c32627f7cfd6ad67f7c86db",
               "81d695146542b67483b432ce2778c62944d711a4ad740be37dd930f9a97b80ca",
               "81d695146542b67483b432ce2778c62944d711a4ad740be37dd930f9a97b80ca",
               "635d1185b1507ca5e08a6771f08595801d8d98145ba78665366e492ee1875317",
               "6e2bb79dcafb019d6bbc34b7a4550cd603852493b5427252ae44301f4ea96db4",
               "13ff0fa4901b81b663311faf1396dbc804f53fd56b6067f73776acc48a54f9f9",
               "b4a68330d3a235ef755fa3229e4492e2b7b824fc576dfe73309f09bce6c7adc7",
               "a6457ca8f7a14ba363e6f8467c020e62425eeec755ee1c7a57068e8952c16672",
               "e667c70c74112ae249dff32805c5767700d25fde443ca513222ec3203ce76872",
               "7586725f6bad44993a942453694e3b8d0ca19c5f480f3a741042b6c5132c55ef",
               "5aa02b23b3c30a8f78317b2942a36206520c513d2bbfa3e1341f4caff749b692",
               "ce12e654c48a7145f456ded3337354227c845c4012a6302fa63e6901c580b610",
               "ed9b5c4a768f2744cc564a8d470af9b2cf259f53a7538adf59cb8f1eaee0217b",
               "7c9f73755aa4e7b0480ca6a1b23b25e3103c17afa1635a3abf8c03bb3a686a78",
               "3885dbec9db4d8a3a1f6ad12ff0055e64de63d351424b954369e7828950f7fa7",
               "ce12e654c48a7145f456ded3337354227c845c4012a6302fa63e6901c580b610",
               "05b5616932031283eea3751dfcad273db805a71b4e35afdbc03bd3c30bc6b6b0",
               "f5924d522b7d8b4a551c2d4045069c9a711b62b97e2b799e7b42a9931e58fba3",
               "0cd9e13dbce7595879d9e972dc04e81da63d1cbf34c99fd3603e2aba68ccf2a5",
               "f6b9cefd13932daad90ac587fec1e5ec542bca1936fcbd3245d0919e48460a9c",
               "c14d07ccccaaab6c4adbfba16b3f977f64408499dce5aa8df424b2c59a313d48") and
 not (process.executable : "?:\\Windows\\Sys*\\msiexec.exe" and dll.path : "C:\\Windows\\Installer\\MSI????.tmp")] by dll.hash.sha256
[api where
 process.Ext.api.behaviors in ("shellcode", "allocate_shellcode", "execute_shellcode") and
 process.thread.Ext.call_stack_final_user_module.hash.sha256 like "?*" and
 not process.thread.Ext.call_stack_final_user_module.protection_provenance like ("Unknown", "issetup.dll", "isrt.dll", "isslideshow.dll", "is_*.tmp") and
 not (process.executable : ("C:\\Windows\\SysWOW64\\msiexec.exe", "C:\\Windows\\System32\\msiexec.exe") and
      (process.thread.Ext.call_stack_final_user_module.name like "msi*.tmp" or process.thread.Ext.call_stack_final_user_module.protection_provenance like "msi*.tmp")) and
 not (process.Ext.api.name == "VirtualAlloc" and process.Ext.api.parameters.size <= 5000) and
 not (process.Ext.api.name == "NtQueueApcThread" and process.executable : "C:\\Windows\\SysWOW64\\msiexec.exe" and
      process.thread.Ext.call_stack_final_user_module.name like "_is*.tmp") and
 not (process.thread.Ext.call_stack_final_user_module.protection_provenance == "bass.dll" and
      process.thread.Ext.call_stack_final_user_module.protection_provenance_path like "c:\\users\\*\\appdata\\local\\temp\\is-*.tmp\\*.tmp") and
 not (process.parent.executable : ("C:\\Program Files\\*", "C:\\Program Files (x86)\\*") and
      process.thread.Ext.call_stack_final_user_module.protection_provenance_path: ("C:\\Program Files\\*", "C:\\Program Files (x86)\\*")) and
 not (process.Ext.api.name == "VirtualProtect" and
       _arraysearch(process.thread.Ext.call_stack, $entry,
                    $entry.symbol_info like ("c:\\windows\\sys?????\\ntdll.dll!LdrLoadDll*",
                                             "c:\\windows\\sys?????\\kernelbase.dll!LoadLibrary*"))) and
 not (process.name : ("msiexec.exe", "setup.exe") and
      _arraysearch(process.thread.Ext.call_stack, $entry, $entry.callsite_trailing_bytes == "8985271f001056e8f60300008d8dbd1d001085c00f859400000056e84003000056e85502000056e85301000090909090909090908b4e3485c90f848900000003"))
 ] by process.thread.Ext.call_stack_final_user_module.hash.sha256
Raw source Shellcode Execution from Low Reputation Module · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = "Identifies attempt to allocate or execute Shellcode from a module with low or unknown reputation."
id = "9fda6a38-3822-45b6-b621-02f750e8cf0d"
license = "Elastic License v2"
name = "Shellcode Execution from Low Reputation Module"
os_list = ["windows"]
reference = [
    "https://www.elastic.co/security-labs/pikabot-i-choose-you",
    "https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus",
]
version = "1.0.21"

query = '''
sequence by process.entity_id with maxspan=1m
[library where
  not dll.code_signature.status == "trusted" and
  not dll.code_signature.status == "errorCode_endpoint: Failure in an external software component" and
  (dll.Ext.relative_file_creation_time <= 3600 or dll.Ext.relative_file_name_modify_time <= 3600) and 
  not dll.path : ("?:\\windows\\assembly\\nativeimages_*", "c:\\windows\\ccmcache\\*") and
  not (dll.path : "?:\\Windows\\Installer\\*.tmp" and process.name : "msiexec.exe") and
  not dll.hash.sha256 in
              ("29ae6f149e581f8dbdc01eed2d5d20b82b597c4b4c7e102cab6d012b168df4d8",
               "e2705efc246b6cd16ec560122d595394bb01de90db963d409c33f5330a871a93",
               "c4fe4ea78a4134349dfa71f4059b6233a8d1bb4b7592b66da89619726131bd2d",
               "2d81ba21fe9a567dd0fc283afaee95320579c2db163499593bfdc9032b29b925",
               "6ee97fdac52b4a673e9289124be4ce86a6d33e460aa71577848880f6f2ea8b99",
               "3b9aef3265246eac39e4bbacba2b057d5fcd1705c32679254e9ab94d267cb0ac",
               "43af7fe8fc892c3c013f2b980b5295d2e13b0c2e1d1123841ede8a62b94f08a4",
               "5acb0c408b3309a313623d05868ca7359dc17cf113461ffa0522f5df10963644",
               "9c973a0aca4147970c3e714a8750fbceda27f6d96fdfb04c8f5f24f66abde6aa",
               "c16f23e42ecdfe6561d2d9c9ce746630252f1ad15fa670d60ef268c1a7819c10",
               "10f5e4152ad9072116c6925defb54ccd56993b33bfad0c80b43cc3ea6daca812",
               "e5c81555bcc87dc59574f546f19af7d9a0ca564b254178148112d79201d2bf9c",
               "0d5d73d3bea132f98be91f918d13043791decb419a81d9e755979315a7cf0502",
               "beea6a901336753d2a9b8802a8cfa88da2619bebf9fafbef6bbab07b0d4eddcb",
               "dfde40ca8128e6cc3b046ede410be4734bc1ba552ce546e62bac40ad7d69dec0",
               "ba877ea99e9ebd794266529dc0228d279219516349fbbefc0bdd5dfd514eb52f",
               "beea6a901336753d2a9b8802a8cfa88da2619bebf9fafbef6bbab07b0d4eddcb",
               "3f2fb2aa90ca14fe598bd2ec32e2fc6818f5784fa0cd69160939b7394a4f8bdd",
               "15efeb9a8ab4d7553ce58e825c7a7ac5852a5a217722d92bdec17a890c2e006d",
               "efd601882adb9cba4adbce6770be1ff62302f3f10321657c527a9c647faccd15",
               "c233341d1b6bee8a61c8748e956d8f9ec6c4c1bb93de0322639da46c8d9bbf92",
               "de7585c96725bbe66e11c3c80aebb66cd61b901d6acf983b63c29e64e0cfbc9c",
               "4c28bcbbbd54e0c7e43cb1cb9980918668ca6cab379ad114e9d1d4640b5ef154",
               "19f75446ac56ee7bf3efe1cc25383fcab91a557f9b6257b39e496ec4a6ff8b2e",
               "e2b761094a6f6300da32e861e8f42c359b22a0cf1d62ff3a2721882aa4d1c2c6",
               "f0997f96bc59a9ff7d7fb8905b79996a179bfaad39a6113c9edf00135a96c561",
               "ef14a3b57cd57f97fea9fcbf81b3350d0f11785ecc27e37085110f380ddcb17d",
               "db3477572af5b5f353e723db1e7e8de9b743a120a145c3c26851e969ac34044d",
               "5655e005145c8a0bd1648bae17d456f14321d054240486dff349253c2c8da087",
               "d57cdf9fe51debc65441be155eddb663cebfaec1c0c91161234dd3398ca71b76",
               "22ee08ed8c02358f994b5deba0940735b161f9a73ad60e4e57d10b9e1988ec83",
               "88f0452c2ac66146139b87e60e9bb8a8b6a6566cbb9040e5e8ee1774e12f35ba",
               "4379d68dde8fb1f022a870947d0524c0ed8a7b37bcfc49772a4d0a4e04158b7b",
               "f7d7680d544e9e8da9b95c8905e5d2ca5adc2a3e700c2e1aa1f99287da0d184c",
               "6f49e3558970540edfb187c59d32f3a27eecc6a48d87b49ad72c19495355f1db",
               "bce30810240512dde3f6513b3734ae0f6b98c35ac5465e5e12262db8a086e37e",
               "32394db9c0677d31efd0d684e969c6fab55fa1c47114c980a9e3f39ff85f2e58",
               "fb6ec0f7104fec7d0963c53754e84dcb13d6d94c0d19762a2f161503ea5e3580",
               "6a1081e60b6c3e22cf58bb21267230c1dd61bb741c32627f7cfd6ad67f7c86db",
               "81d695146542b67483b432ce2778c62944d711a4ad740be37dd930f9a97b80ca",
               "81d695146542b67483b432ce2778c62944d711a4ad740be37dd930f9a97b80ca",
               "635d1185b1507ca5e08a6771f08595801d8d98145ba78665366e492ee1875317",
               "6e2bb79dcafb019d6bbc34b7a4550cd603852493b5427252ae44301f4ea96db4",
               "13ff0fa4901b81b663311faf1396dbc804f53fd56b6067f73776acc48a54f9f9",
               "b4a68330d3a235ef755fa3229e4492e2b7b824fc576dfe73309f09bce6c7adc7",
               "a6457ca8f7a14ba363e6f8467c020e62425eeec755ee1c7a57068e8952c16672",
               "e667c70c74112ae249dff32805c5767700d25fde443ca513222ec3203ce76872",
               "7586725f6bad44993a942453694e3b8d0ca19c5f480f3a741042b6c5132c55ef",
               "5aa02b23b3c30a8f78317b2942a36206520c513d2bbfa3e1341f4caff749b692",
               "ce12e654c48a7145f456ded3337354227c845c4012a6302fa63e6901c580b610",
               "ed9b5c4a768f2744cc564a8d470af9b2cf259f53a7538adf59cb8f1eaee0217b",
               "7c9f73755aa4e7b0480ca6a1b23b25e3103c17afa1635a3abf8c03bb3a686a78",
               "3885dbec9db4d8a3a1f6ad12ff0055e64de63d351424b954369e7828950f7fa7",
               "ce12e654c48a7145f456ded3337354227c845c4012a6302fa63e6901c580b610",
               "05b5616932031283eea3751dfcad273db805a71b4e35afdbc03bd3c30bc6b6b0",
               "f5924d522b7d8b4a551c2d4045069c9a711b62b97e2b799e7b42a9931e58fba3",
               "0cd9e13dbce7595879d9e972dc04e81da63d1cbf34c99fd3603e2aba68ccf2a5",
               "f6b9cefd13932daad90ac587fec1e5ec542bca1936fcbd3245d0919e48460a9c",
               "c14d07ccccaaab6c4adbfba16b3f977f64408499dce5aa8df424b2c59a313d48") and
 not (process.executable : "?:\\Windows\\Sys*\\msiexec.exe" and dll.path : "C:\\Windows\\Installer\\MSI????.tmp")] by dll.hash.sha256
[api where
 process.Ext.api.behaviors in ("shellcode", "allocate_shellcode", "execute_shellcode") and
 process.thread.Ext.call_stack_final_user_module.hash.sha256 like "?*" and
 not process.thread.Ext.call_stack_final_user_module.protection_provenance like ("Unknown", "issetup.dll", "isrt.dll", "isslideshow.dll", "is_*.tmp") and
 not (process.executable : ("C:\\Windows\\SysWOW64\\msiexec.exe", "C:\\Windows\\System32\\msiexec.exe") and
      (process.thread.Ext.call_stack_final_user_module.name like "msi*.tmp" or process.thread.Ext.call_stack_final_user_module.protection_provenance like "msi*.tmp")) and
 not (process.Ext.api.name == "VirtualAlloc" and process.Ext.api.parameters.size <= 5000) and
 not (process.Ext.api.name == "NtQueueApcThread" and process.executable : "C:\\Windows\\SysWOW64\\msiexec.exe" and
      process.thread.Ext.call_stack_final_user_module.name like "_is*.tmp") and
 not (process.thread.Ext.call_stack_final_user_module.protection_provenance == "bass.dll" and
      process.thread.Ext.call_stack_final_user_module.protection_provenance_path like "c:\\users\\*\\appdata\\local\\temp\\is-*.tmp\\*.tmp") and
 not (process.parent.executable : ("C:\\Program Files\\*", "C:\\Program Files (x86)\\*") and
      process.thread.Ext.call_stack_final_user_module.protection_provenance_path: ("C:\\Program Files\\*", "C:\\Program Files (x86)\\*")) and
 not (process.Ext.api.name == "VirtualProtect" and
       _arraysearch(process.thread.Ext.call_stack, $entry,
                    $entry.symbol_info like ("c:\\windows\\sys?????\\ntdll.dll!LdrLoadDll*",
                                             "c:\\windows\\sys?????\\kernelbase.dll!LoadLibrary*"))) and
 not (process.name : ("msiexec.exe", "setup.exe") and
      _arraysearch(process.thread.Ext.call_stack, $entry, $entry.callsite_trailing_bytes == "8985271f001056e8f60300008d8dbd1d001085c00f859400000056e84003000056e85502000056e85301000090909090909090908b4e3485c90f848900000003"))
 ] by process.thread.Ext.call_stack_final_user_module.hash.sha256
'''

min_endpoint_version = "8.14.2"
reputation = true
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[optional_actions]]
action = "rollback"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1055"
name = "Process Injection"
reference = "https://attack.mitre.org/techniques/T1055/"

[[threat.technique]]
id = "T1574"
name = "Hijack Execution Flow"
reference = "https://attack.mitre.org/techniques/T1574/"
[[threat.technique.subtechnique]]
id = "T1574.001"
name = "DLL"
reference = "https://attack.mitre.org/techniques/T1574/001/"



[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"

[internal]
min_endpoint_version = "8.14.2"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.