Windows file access indicators tied to CVE-2021-31979 and CVE-2021-33771 exploitation
Flags Windows file events where the target filename matches paths tied to CVE-2021-31979/CVE-2021-33771 exploitation patterns.
FreeUnreviewedSigmacriticalv1
windows-file-access-indicators-tied-to-cve-2021-31979-and-cve-2021-33771-exploit-ad7085ac
title: Windows file access indicators tied to CVE-2021-31979 and CVE-2021-33771 exploitation
id: ef2e6a93-d3e2-448e-a3ea-4992c079c189
status: test
description: This rule identifies Windows file event activity matching specific on-disk paths and filenames associated with exploitation patterns observed for CVE-2021-31979 and CVE-2021-33771. Attackers may use these file targets as part of a staged payload or post-compromise execution workflow, so matching them in file telemetry can help surface likely exploitation attempts. The detection relies on Windows file event logging and searches for contains matches within the target filename.
references:
- https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/
- https://citizenlab.ca/2021/07/hooking-candiru-another-mercenary-spyware-vendor-comes-into-focus/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-33771/file_event_win_cve_2021_31979_cve_2021_33771_exploits.yml
author: Sittikorn S, Huntrule Team
date: 2021-07-16
modified: 2022-10-09
tags:
- attack.initial-access
- attack.execution
- attack.credential-access
- attack.t1566
- attack.t1203
- cve.2021-33771
- cve.2021-31979
- detection.emerging-threats
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|contains:
- C:\Windows\system32\physmem.sys
- C:\Windows\System32\IME\IMEJP\imjpueact.dll
- C:\Windows\system32\ime\IMETC\IMTCPROT.DLL
- C:\Windows\system32\ime\SHARED\imecpmeid.dll
- C:\Windows\system32\config\spp\ServiceState\Recovery\pac.dat
- C:\Windows\system32\config\cy-GB\Setup\SKB\InputMethod\TupTask.dat
- C:\Windows\system32\config\config\startwus.dat
- C:\Windows\system32\ime\SHARED\WimBootConfigurations.ini
- C:\Windows\system32\ime\IMEJP\WimBootConfigurations.ini
- C:\Windows\system32\ime\IMETC\WimBootConfigurations.ini
condition: selection
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: ad7085ac-92e4-4b76-8ce2-276d2c0e68ef
type: derived
What it detects
This rule identifies Windows file event activity matching specific on-disk paths and filenames associated with exploitation patterns observed for CVE-2021-31979 and CVE-2021-33771. Attackers may use these file targets as part of a staged payload or post-compromise execution workflow, so matching them in file telemetry can help surface likely exploitation attempts. The detection relies on Windows file event logging and searches for contains matches within the target filename.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.