Potential COM Objects Download Cradles Usage - Process Creation

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects usage of COM objects that can be abused to download files in PowerShell by CLSID

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Process started" AND COMMANDLINE contains "[Type]::GetTypeFromCLSID(" AND COMMANDLINE contains "0002DF01-0000-0000-C000-000000000046,F6D90F16-9C73-11D3-B32E-00C04F990BB4,F5078F35-C551-11D3-89B9-0000F81FE221,88d96a0a-f192-11d4-a65f-0040963251e5,AFBA6B42-5692-48EA-8141-DC517DCF0EF1,AFB40FFD-B609-40A3-9828-F88BBE11E4E3,88d96a0b-f192-11d4-a65f-0040963251e5,2087c2f4-2cef-4953-a8ab-66779b670495,000209FF-0000-0000-C000-000000000046,00024500-0000-0000-C000-000000000046" select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

frack113