{"id":"14bcba49-a428-42d9-b943-e2ce0f0f7ae6","title":"Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System","description":"Detects Obfuscated Powershell via VAR++ LAUNCHER","author":"Timur Zinniatullin, oscd.community","status":"test","level":"high","date":"2020-10-13","modified":"2022-11-29","tags":["attack.stealth","attack.t1027","attack.execution","attack.t1059.001"],"technique_ids":["T1027","T1059.001"],"logsource":{"product":"windows","service":"system"},"falsepositives":["Unknown"],"references":["https://github.com/SigmaHQ/sigma/issues/1009"],"source_path":"rules/windows/builtin/system/service_control_manager/win_system_invoke_obfuscation_via_var_services.yml","source_sha256":"6e32b7a5a7449e561dbf25a1fa4a61a8b17dac586234f550258517936b19f878","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/system/service_control_manager/win_system_invoke_obfuscation_via_var_services.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System\nid: 14bcba49-a428-42d9-b943-e2ce0f0f7ae6\nstatus: test\ndescription: Detects Obfuscated Powershell via VAR++ LAUNCHER\nreferences:\n    - https://github.com/SigmaHQ/sigma/issues/1009 # (Task27)\nauthor: Timur Zinniatullin, oscd.community\ndate: 2020-10-13\nmodified: 2022-11-29\ntags:\n    - attack.stealth\n    - attack.t1027\n    - attack.execution\n    - attack.t1059.001\nlogsource:\n    product: windows\n    service: system\ndetection:\n    selection:\n        Provider_Name: 'Service Control Manager'\n        EventID: 7045\n        # ImagePath|re: '(?i)&&set.*(\\{\\d\\}){2,}\\\\\\\"\\s+?\\-f.*&&.*cmd.*\\/c' # FPs with |\\/r\n        # Example 1: CMD /C\"sET KUR=Invoke-Expression (New-Object Net.WebClient).DownloadString&&Set MxI=C:\\wINDowS\\sYsWow64\\winDOWspoWERSheLl\\V1.0\\PowerShelL.EXe ${ExEcut`IoN`cON`TExT}.\\\"invo`kEcoMm`A`ND\\\".( \\\"{2}{1}{0}\\\" -f 'pt','EscRi','INvOk' ).Invoke( ( .( \\\"{0}{1}\\\" -f'D','IR' ) ( \\\"{0}{1}\\\"-f'ENV:kU','R')).\\\"vAl`Ue\\\" )&& CMD /C%mXI%\"\n        # Example 2: c:\\WiNDOWS\\sYSTEm32\\CmD.exE /C \"sEt DeJLz=Invoke-Expression (New-Object Net.WebClient).DownloadString&&set yBKM=PoWERShelL -noeX ^^^&(\\\"{2}{0}{1}\\\"-f '-ItE','m','seT') ( 'V' + 'a'+ 'RiAblE:z8J' +'U2' + 'l' ) ([TYpE]( \\\"{2}{3}{0}{1}\\\"-f 'e','NT','e','NViRONM' ) ) ; ^^^& ( ( [sTrIng]${VE`Rbo`SepReFER`Ence})[1,3] + 'X'-joIN'')( ( (.('gI') ('V' + 'a' + 'RIAbLe:z8j' + 'u2' +'l' ) ).vALUe::( \\\"{2}{5}{0}{1}{6}{4}{3}\\\" -f 'IRo','Nm','GETE','ABlE','I','nv','enTVAr').Invoke(( \\\"{0}{1}\\\"-f'd','ejLz' ),( \\\"{1}{2}{0}\\\"-f'cEss','P','RO') )) )&& c:\\WiNDOWS\\sYSTEm32\\CmD.exE /C %ybkm%\"\n        ImagePath|contains|all:\n            - '&&set'\n            - 'cmd'\n            - '/c'\n            - '-f'\n        ImagePath|contains:\n            - '{0}'\n            - '{1}'\n            - '{2}'\n            - '{3}'\n            - '{4}'\n            - '{5}'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1027","id":"T1027","name":"Obfuscated Files or Information","page":"techniques/enterprise/T1027/"},{"key":"enterprise/T1059.001","id":"T1059.001","name":"PowerShell","page":"techniques/enterprise/T1059.001/"}],"data_path":"data/detection-rules/14bcba49-a428-42d9-b943-e2ce0f0f7ae6.json","kind":"sigma"}
