Detection rules › Sigma

Wab/Wabmig Unusual Parent Or Child Processes

Status
test
Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects unusual parent or children of the wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) processes as seen being used with bumblebee activity

Event coverage

Rule body yaml

title: Wab/Wabmig Unusual Parent Or Child Processes
id: 63d1ccc0-2a43-4f4b-9289-361b308991ff
status: test
description: Detects unusual parent or children of the wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) processes as seen being used with bumblebee activity
references:
    - https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/
    - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bumblebee-loader-cybercrime
    - https://thedfirreport.com/2022/09/26/bumblebee-round-two/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-08-12
modified: 2022-09-27
tags:
    - attack.execution
    - attack.stealth
logsource:
    category: process_creation
    product: windows
detection:
    selection_parent:
        ParentImage|endswith:
            # Add more if known
            - \WmiPrvSE.exe
            - \svchost.exe
            - \dllhost.exe
        Image|endswith:
            - '\wab.exe'
            - '\wabmig.exe' # (Microsoft Address Book Import Tool)
    selection_child:
        # You can add specific suspicious child processes (such as cmd, powershell...) to increase the accuracy
        ParentImage|endswith:
            - '\wab.exe'
            - '\wabmig.exe' # (Microsoft Address Book Import Tool)
    condition: 1 of selection_*
falsepositives:
    - Unknown
level: high

Stages and Predicates

Stage 0: condition

1 of selection_*

Stage 1: selection_parent

selection_parent:
    ParentImage|endswith:
        # Add more if known
        - \WmiPrvSE.exe
        - \svchost.exe
        - \dllhost.exe
    Image|endswith:
        - '\wab.exe'
        - '\wabmig.exe' # (Microsoft Address Book Import Tool)

Stage 2: selection_child

selection_child:
    # You can add specific suspicious child processes (such as cmd, powershell...) to increase the accuracy
    ParentImage|endswith:
        - '\wab.exe'
        - '\wabmig.exe' # (Microsoft Address Book Import Tool)

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
Imageends_with
  • \wab.exe corpus 3 (sigma 3)
  • \wabmig.exe corpus 3 (sigma 3)
ParentImageends_with
  • \WmiPrvSE.exe corpus 8 (sigma 8)
  • \dllhost.exe corpus 7 (sigma 7)
  • \svchost.exe corpus 14 (sigma 14)
  • \wab.exe
  • \wabmig.exe