← Back to Explore
sigmahighHunting
PrintBrm ZIP Creation of Extraction
Detects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.
Detection Query
selection:
Image|endswith: \PrintBrm.exe
CommandLine|contains|all:
- " -f"
- .zip
condition: selection
Author
frack113
Created
2022-05-02
Data Sources
windowsProcess Creation Events
Platforms
windows
Tags
attack.command-and-controlattack.t1105attack.defense-evasionattack.t1564.004
Raw Content
title: PrintBrm ZIP Creation of Extraction
id: cafeeba3-01da-4ab4-b6c4-a31b1d9730c7
status: test
description: Detects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.
references:
- https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/
author: frack113
date: 2022-05-02
tags:
- attack.command-and-control
- attack.t1105
- attack.defense-evasion
- attack.t1564.004
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '\PrintBrm.exe'
CommandLine|contains|all:
- ' -f'
- '.zip'
condition: selection
falsepositives:
- Unknown
level: high