title: Arbitrary File Download Via MSPUB.EXE id: 3b3c7f55-f771-4dd6-8a6e-08d057a17caf status: test description: Detects usage of "MSPUB" (Microsoft Publisher) to download arbitrary files references: - https://github.com/LOLBAS-Project/LOLBAS/pull/238/files author: Nasreddine Bencherchali (Nextron Systems) date: 2022-08-19 modified: 2023-02-08 tags: - attack.defense-evasion - attack.execution - attack.t1218 logsource: category: process_creation product: windows detection: selection_img: - Image|endswith: '\MSPUB.exe' - OriginalFileName: 'MSPUB.exe' selection_cli: CommandLine|contains: - 'ftp://' - 'http://' - 'https://' condition: all of selection_* falsepositives: - Unknown level: medium