Detection rules › Sigma

Uncommon Child Process Of Appvlp.EXE

Status
test
Severity
medium
Log source
product windows, category process_creation
Author
Sreeman
Source
github.com/SigmaHQ/sigma

Detects uncommon child processes of Appvlp.EXE Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands. Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder or to mark a file as a system file.

MITRE ATT&CK coverage

Event coverage

Rule body yaml

title: Uncommon Child Process Of Appvlp.EXE
id: 9c7e131a-0f2c-4ae0-9d43-b04f4e266d43
status: test
description: |
    Detects uncommon child processes of Appvlp.EXE
    Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands.
    Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder
    or to mark a file as a system file.
references:
    - https://lolbas-project.github.io/lolbas/OtherMSBinaries/Appvlp/
author: Sreeman
date: 2020-03-13
modified: 2023-11-09
tags:
    - attack.stealth
    - attack.t1218
    - attack.execution
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        ParentImage|endswith: '\appvlp.exe'
    # Note: Filters based on data from EchoTrail: https://www.echotrail.io/insights/search/appvlp.exe/
    filter_main_generic:
        Image|endswith:
            - ':\Windows\SysWOW64\rundll32.exe'
            - ':\Windows\System32\rundll32.exe'
    filter_optional_office_msoasb:
        Image|contains: ':\Program Files\Microsoft Office'
        Image|endswith: '\msoasb.exe'
    filter_optional_office_skype:
        Image|contains|all:
            - ':\Program Files\Microsoft Office'
            - '\SkypeSrv\'
        Image|endswith: '\SKYPESERVER.EXE'
    filter_optional_office_msouc:
        Image|contains: ':\Program Files\Microsoft Office'
        Image|endswith: '\MSOUC.EXE'
    condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
    - Unknown
level: medium

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_main_* and not 1 of filter_optional_*

Stage 1: selection

selection:
    ParentImage|endswith: '\appvlp.exe'

Stage 2: not filter_main_generic

filter_main_generic:
    Image|endswith:
        - ':\Windows\SysWOW64\rundll32.exe'
        - ':\Windows\System32\rundll32.exe'

Stage 3: not filter_optional_*

filter_optional_office_msoasb:
    Image|contains: ':\Program Files\Microsoft Office'
    Image|endswith: '\msoasb.exe'
filter_optional_office_skype:
    Image|contains|all:
        - ':\Program Files\Microsoft Office'
        - '\SkypeSrv\'
    Image|endswith: '\SKYPESERVER.EXE'
filter_optional_office_msouc:
    Image|contains: ':\Program Files\Microsoft Office'
    Image|endswith: '\MSOUC.EXE'

Exclusions

Top-level NOT(...) conjuncts: predicates this rule actively suppresses.

FieldKindExcluded values
Imageends_with:\Windows\SysWOW64\rundll32.exe
Imageends_with:\Windows\System32\rundll32.exe
Imageends_with\MSOUC.EXE
Imagematch:\Program Files\Microsoft Office
Imageends_with\SKYPESERVER.EXE
Imagematch:\Program Files\Microsoft Office
Imagematch\SkypeSrv\
Imageends_with\msoasb.exe
Imagematch:\Program Files\Microsoft Office

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
ParentImageends_with
  • \appvlp.exe