Analytics BIOC Low

Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer

A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Privilege Escalation (TA0004)
ATT&CK techniques: Process Injection: Portable Executable Injection (T1055.002)
Detector tags: Injection Analytics
Attacker's goals:

Gain code execution on the host in the context of another process.

Investigative actions:

Investigate the acting process for other malicious activities. Check if the target process was injected and for anomalies in its behavior after this event.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an office process High (parent: Low)
  • Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an injected thread Medium (parent: Low)
  • Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from a LOLBIN process Medium (parent: Low)
  • Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer from an unsigned process Medium (parent: Low)