Windows file access indicators tied to CVE-2021-31979 and CVE-2021-33771 exploitation

Flags Windows file events where the target filename matches paths tied to CVE-2021-31979/CVE-2021-33771 exploitation patterns.

FreeUnreviewedSigmacriticalv1
title: Windows file access indicators tied to CVE-2021-31979 and CVE-2021-33771 exploitation
id: ef2e6a93-d3e2-448e-a3ea-4992c079c189
status: test
description: This rule identifies Windows file event activity matching specific on-disk paths and filenames associated with exploitation patterns observed for CVE-2021-31979 and CVE-2021-33771. Attackers may use these file targets as part of a staged payload or post-compromise execution workflow, so matching them in file telemetry can help surface likely exploitation attempts. The detection relies on Windows file event logging and searches for contains matches within the target filename.
references:
  - https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
  - https://citizenlab.ca/2021/07/hooking-candiru-another-mercenary-spyware-vendor-comes-into-focus/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-33771/file_event_win_cve_2021_31979_cve_2021_33771_exploits.yml
author: Sittikorn S, Huntrule Team
date: 2021-07-16
modified: 2022-10-09
tags:
  - attack.initial-access
  - attack.execution
  - attack.credential-access
  - attack.t1566
  - attack.t1203
  - cve.2021-33771
  - cve.2021-31979
  - detection.emerging-threats
logsource:
  product: windows
  category: file_event
detection:
  selection:
    TargetFilename|contains:
      - C:\Windows\system32\physmem.sys
      - C:\Windows\System32\IME\IMEJP\imjpueact.dll
      - C:\Windows\system32\ime\IMETC\IMTCPROT.DLL
      - C:\Windows\system32\ime\SHARED\imecpmeid.dll
      - C:\Windows\system32\config\spp\ServiceState\Recovery\pac.dat
      - C:\Windows\system32\config\cy-GB\Setup\SKB\InputMethod\TupTask.dat
      - C:\Windows\system32\config\config\startwus.dat
      - C:\Windows\system32\ime\SHARED\WimBootConfigurations.ini
      - C:\Windows\system32\ime\IMEJP\WimBootConfigurations.ini
      - C:\Windows\system32\ime\IMETC\WimBootConfigurations.ini
  condition: selection
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: ad7085ac-92e4-4b76-8ce2-276d2c0e68ef
    type: derived

What it detects

This rule identifies Windows file event activity matching specific on-disk paths and filenames associated with exploitation patterns observed for CVE-2021-31979 and CVE-2021-33771. Attackers may use these file targets as part of a staged payload or post-compromise execution workflow, so matching them in file telemetry can help surface likely exploitation attempts. The detection relies on Windows file event logging and searches for contains matches within the target filename.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.