Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0029 — Detect Persistence via Outlook Custom Forms Triggered by Malicious Email
DET0029

Detect Persistence via Outlook Custom Forms Triggered by Malicious Email

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0085 Analytic 0085
Windows

Adversary uses a tool like Ruler to insert a malicious custom form into the user's Outlook mailbox. The form is designed to auto-execute on Outlook startup or on receipt of a specially crafted email. This results in child processes launched from outlook.exe and possibly network connections or payload loading.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7 WinEventLog:Application Outlook errors loading or processing custom form templates WinEventLog:PowerShell Execution of Microsoft script to enumerate custom forms in Outlook mailbox
[FormStorageLocation] Malicious forms may be stored in various user-specific locations in the Outlook mailbox (e.g., IPM.Note class)
[ChildProcessName] Child process spawned by outlook.exe may vary (e.g., powershell.exe, rundll32.exe, mshta.exe)
[TimeWindow] Form-triggered execution may happen immediately upon Outlook startup or with delay after crafted message arrival
[OutlookVersion] Form behavior and error logs may vary across Outlook 2013, 2016, and M365 builds
[UserContext] Attack may target only specific users; contextual correlation needed for account baselining
AN0086 Analytic 0086
Office Suite

Outlook form execution upon message receipt or client launch results in automated code execution within user session. Form definitions deviate from standard templates and include script logic or COM object calls embedded in form fields.

m365:unified Unusual form activity within Outlook client, including load of non-default forms m365:messagetrace Inbound email triggers execution of mailbox-stored custom form
[AuditPolicyScope] Not all tenants may enable audit logs of custom form activity or COM component usage in Office
[MessageSenderAnomalyThreshold] Ruler-style delivery may come from external accounts with forged headers or low reputation
[FormExecutionRate] Frequency of form triggers may be anomalously high compared to baseline Outlook usage

Detected Techniques

1

Details

MITRE ID
DET0029
STIX ID
x-mitre-detection-strategy--75281b94-735d-4051-b400-a42205783af9
Analytics
2
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.