Merge PR #4239 From @greg-workspace - Add Rule Related To CVE-2023-27363
new: Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReader --------- Co-authored-by: Greg <greg@MBP13-2020.local> Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com> Co-authored-by: phantinuss <79651203+phantinuss@users.noreply.github.com>
This commit is contained in:
+26
@@ -0,0 +1,26 @@
|
||||
title: Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReader
|
||||
id: 9cae055f-e1d2-4f81-b8a5-1986a68cdd84
|
||||
status: experimental
|
||||
description: Detects suspicious ".hta" file creation in the startup folder by Foxit Reader. This can be an indication of CVE-2023-27363 exploitation.
|
||||
references:
|
||||
- https://github.com/j00sean/SecBugs/tree/ff72d553f75d93e1a0652830c0f74a71b3f19c46/CVEs/CVE-2023-27363
|
||||
- https://www.zerodayinitiative.com/advisories/ZDI-23-491/
|
||||
- https://www.tarlogic.com/blog/cve-2023-27363-foxit-reader/
|
||||
author: Gregory
|
||||
date: 2023/10/11
|
||||
tags:
|
||||
- attack.persistence
|
||||
- attack.t1505.001
|
||||
- cve.2023.27363
|
||||
logsource:
|
||||
product: windows
|
||||
category: file_event
|
||||
detection:
|
||||
selection:
|
||||
Image|endswith: '\FoxitPDFReader.exe'
|
||||
TargetFilename|contains: '\Microsoft\Windows\Start Menu\Programs\Startup\'
|
||||
TargetFilename|endswith: '.hta'
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
level: high
|
||||
Reference in New Issue
Block a user