Detection rules › Sigma

Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process

Status
test
Severity
medium
Log source
category image_load, product windows
Author
Perez Diego (@darkquassar), oscd.community, Ecco
Source
github.com/SigmaHQ/sigma

Detects the load of dbghelp/dbgcore DLL by a potentially uncommon or potentially suspicious process. The Dbghelp and Dbgcore DLLs export functions that allow for the dump of process memory. Tools like ProcessHacker, Task Manager and some attacker tradecraft use the MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine. Keep in mind that many legitimate Windows processes and services might load the aforementioned DLLs for debugging or other related purposes. Investigate the CommandLine and the Image location of the process loading the DLL.

Known false positives

  • Debugging scripts might leverage this DLL in order to dump process memory for further analysis.

MITRE ATT&CK coverage

TacticTechniques
Credential Access

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 7: Image loaded

Rule body

title: Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process
id: 0e277796-5f23-4e49-a490-483131d4f6e1
related:
    - id: bdc64095-d59a-42a2-8588-71fd9c9d9abc # Unsigned Loading
      type: similar
status: test
description: |
    Detects the load of dbghelp/dbgcore DLL by a potentially uncommon or potentially suspicious process.
    The Dbghelp and Dbgcore DLLs export functions that allow for the dump of process memory. Tools like ProcessHacker, Task Manager and some attacker tradecraft use the MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll.
    As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine.
    Keep in mind that many legitimate Windows processes and services might load the aforementioned DLLs for debugging or other related purposes. Investigate the CommandLine and the Image location of the process loading the DLL.
references:
    - https://docs.microsoft.com/en-us/windows/win32/api/minidumpapiset/nf-minidumpapiset-minidumpwritedump
    - https://www.pinvoke.net/default.aspx/dbghelp/MiniDumpWriteDump.html
    - https://medium.com/@fsx30/bypass-edrs-memory-protection-introduction-to-hooking-2efb21acffd6
author: Perez Diego (@darkquassar), oscd.community, Ecco
date: 2019-10-27
modified: 2024-03-01
tags:
    - attack.credential-access
    - attack.t1003.001
    - detection.threat-hunting
logsource:
    category: image_load
    product: windows
detection:
    selection:
        ImageLoaded|endswith:
            - '\dbghelp.dll'
            - '\dbgcore.dll'
        Image|endswith:
            - '\bash.exe'
            - '\cmd.exe'
            - '\cscript.exe'
            - '\dnx.exe'
            - '\excel.exe'
            - '\monitoringhost.exe'
            - '\msbuild.exe'
            - '\mshta.exe'
            - '\outlook.exe'
            - '\powerpnt.exe'
            - '\regsvcs.exe'
            - '\rundll32.exe'
            - '\sc.exe'
            - '\scriptrunner.exe'
            - '\winword.exe'
            - '\wmic.exe'
            - '\wscript.exe'
            # - '\powershell.exe' # Note: Triggered by installing common software
            # - '\regsvr32.exe'  # Note: triggered by installing common software
            # - '\schtasks.exe'  # Note: triggered by installing software
            # - '\svchost.exe'  # Note: triggered by some services
    filter_main_tiworker:
        # Note: This filter requires "CommandLine" field enrichment
        CommandLine|startswith: 'C:\WINDOWS\WinSxS\'
        CommandLine|endswith: '\TiWorker.exe -Embedding'
    filter_main_generic:
        # Note: This filter requires "CommandLine" field enrichment
        Image|endswith: '\svchost.exe'
        CommandLine|endswith:
            - '-k LocalServiceNetworkRestricted'
            - '-k WerSvcGroup'
    filter_main_rundll32:
        # Note: This filter requires "CommandLine" field enrichment
        Image|endswith: '\rundll32.exe'
        CommandLine|contains:
            - '/d srrstr.dll,ExecuteScheduledSPPCreation'
            - 'aepdu.dll,AePduRunUpdate'
            - 'shell32.dll,OpenAs_RunDL'
            - 'Windows.Storage.ApplicationData.dll,CleanupTemporaryState'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Debugging scripts might leverage this DLL in order to dump process memory for further analysis.
level: medium

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_main_*

Stage 1: selection

selection:
    ImageLoaded|endswith:
        - '\dbghelp.dll'
        - '\dbgcore.dll'
    Image|endswith:
        - '\bash.exe'
        - '\cmd.exe'
        - '\cscript.exe'
        - '\dnx.exe'
        - '\excel.exe'
        - '\monitoringhost.exe'
        - '\msbuild.exe'
        - '\mshta.exe'
        - '\outlook.exe'
        - '\powerpnt.exe'
        - '\regsvcs.exe'
        - '\rundll32.exe'
        - '\sc.exe'
        - '\scriptrunner.exe'
        - '\winword.exe'
        - '\wmic.exe'
        - '\wscript.exe'

Stage 2: not filter_main_*

filter_main_tiworker:
    CommandLine|startswith: 'C:\WINDOWS\WinSxS\'
    CommandLine|endswith: '\TiWorker.exe -Embedding'
filter_main_generic:
    Image|endswith: '\svchost.exe'
    CommandLine|endswith:
        - '-k LocalServiceNetworkRestricted'
        - '-k WerSvcGroup'
filter_main_rundll32:
    Image|endswith: '\rundll32.exe'
    CommandLine|contains:
        - '/d srrstr.dll,ExecuteScheduledSPPCreation'
        - 'aepdu.dll,AePduRunUpdate'
        - 'shell32.dll,OpenAs_RunDL'
        - 'Windows.Storage.ApplicationData.dll,CleanupTemporaryState'

Exclusions

The rule actively suppresses these predicates.

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
Imageends_with
  • \bash.exe corpus 21 (sigma 21)
  • \cmd.exe corpus 130 (sigma 130)
  • \cscript.exe corpus 72 (sigma 72)
  • \dnx.exe corpus 2 (sigma 2)
  • \excel.exe corpus 16 (sigma 16)
  • \monitoringhost.exe
  • \msbuild.exe corpus 9 (sigma 9)
  • \mshta.exe corpus 66 (sigma 66)
  • \outlook.exe corpus 13 (sigma 13)
  • \powerpnt.exe corpus 14 (sigma 14)
  • \regsvcs.exe corpus 8 (sigma 8)
  • \rundll32.exe corpus 94 (sigma 94)
  • \sc.exe corpus 30 (sigma 30)
  • \scriptrunner.exe corpus 12 (sigma 12)
  • \winword.exe corpus 17 (sigma 17)
  • \wmic.exe corpus 62 (sigma 62)
  • \wscript.exe corpus 74 (sigma 74)
field:"Image" kind:ends_with
ImageLoadedends_with
  • \dbgcore.dll corpus 6 (sigma 6)
  • \dbghelp.dll corpus 6 (sigma 6)
field:"ImageLoaded" kind:ends_with