EXPLORE
← Back to Explore
sigmahighHunting

Suspicious Environment Variable Has Been Registered

Detects the creation of user-specific or system-wide environment variables via the registry. Which contains suspicious commands and strings

Detection Query

selection_main:
  TargetObject|contains: \Environment\
selection_details:
  - Details:
      - powershell
      - pwsh
  - Details|contains:
      - \AppData\Local\Temp\
      - C:\Users\Public\
      - TVqQAAMAAAAEAAAA
      - TVpQAAIAAAAEAA8A
      - TVqAAAEAAAAEABAA
      - TVoAAAAAAAAAAAAA
      - TVpTAQEAAAAEAAAA
      - SW52b2tlL
      - ludm9rZS
      - JbnZva2Ut
      - SQBuAHYAbwBrAGUALQ
      - kAbgB2AG8AawBlAC0A
      - JAG4AdgBvAGsAZQAtA
  - Details|startswith:
      - SUVY
      - SQBFAF
      - SQBuAH
      - cwBhA
      - aWV4
      - aQBlA
      - R2V0
      - dmFy
      - dgBhA
      - dXNpbm
      - H4sIA
      - Y21k
      - cABhAH
      - Qzpc
      - Yzpc
condition: all of selection_*

Author

Nasreddine Bencherchali (Nextron Systems)

Created

2022-12-20

Data Sources

windowsRegistry Set Events

Platforms

windows

Tags

attack.defense-evasionattack.persistence
Raw Content
title: Suspicious Environment Variable Has Been Registered
id: 966315ef-c5e1-4767-ba25-fce9c8de3660
status: test
description: Detects the creation of user-specific or system-wide environment variables via the registry. Which contains suspicious commands and strings
references:
    - https://infosec.exchange/@sbousseaden/109542254124022664
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-12-20
modified: 2023-08-17
tags:
    - attack.defense-evasion
    - attack.persistence
logsource:
    product: windows
    category: registry_set
detection:
    selection_main:
        TargetObject|contains: '\Environment\'
    selection_details:
        - Details:
              - 'powershell'
              - 'pwsh'
        - Details|contains:
              # Add more suspicious strings in env variables below
              - '\AppData\Local\Temp\'
              - 'C:\Users\Public\'
              # Base64 MZ Header
              - 'TVqQAAMAAAAEAAAA' # MZ..........
              - 'TVpQAAIAAAAEAA8A'
              - 'TVqAAAEAAAAEABAA'
              - 'TVoAAAAAAAAAAAAA'
              - 'TVpTAQEAAAAEAAAA'
              # Base64 Invoke- (UTF-8)
              - 'SW52b2tlL'
              - 'ludm9rZS'
              - 'JbnZva2Ut'
              # Base64 Invoke- (UTF-16LE)
              - 'SQBuAHYAbwBrAGUALQ'
              - 'kAbgB2AG8AawBlAC0A'
              - 'JAG4AdgBvAGsAZQAtA'
        - Details|startswith:  # https://gist.github.com/Neo23x0/6af876ee72b51676c82a2db8d2cd3639
              - 'SUVY'
              - 'SQBFAF'
              - 'SQBuAH'
              - 'cwBhA'
              - 'aWV4'
              - 'aQBlA'
              - 'R2V0'
              - 'dmFy'
              - 'dgBhA'
              - 'dXNpbm'
              - 'H4sIA'
              - 'Y21k'
              - 'cABhAH'
              - 'Qzpc'
              - 'Yzpc'
    condition: all of selection_*
falsepositives:
    - Unknown
level: high