Analytics BIOC Low

Office process spawned with suspicious command-line arguments

An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Process Injection: Process Hollowing (T1055.012)
Attacker's goals:

Execute arbitrary code or run malicious applications undetected.

Investigative actions:

Check the file that spawns the office application and search for macros, formulas, or scripts.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Masqueraded office process spawned with suspicious command-line arguments Medium (parent: Low) Adds Masquerading (T1036)
  • PowerPoint process accesses a suspicious PPAM file Low