Sigma Rule Library

Potentially Suspicious Mofcomp Execution

Detects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline. The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Attackers abuse this utility to install malicious MOF scripts

View on GitHubOpen raw file

Detection logic

selection_img

- Image|endswith: \mofcomp.exe
- OriginalFileName: mofcomp.exe

selection_case

- ParentImage|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
    - \wsl.exe
    - \wscript.exe
    - \cscript.exe
- CommandLine|contains:
    - \AppData\Local\Temp
    - \Contacts\
    - \Favorites\
    - \Favourites\
    - \Music\
    - \Pictures\
    - \Users\Public\
    - \Videos\
    - \WINDOWS\Temp\
    - "%appdata%"
    - "%temp%"
    - "%tmp%"

filter_main_wmiprvse

ParentImage: C:\Windows\System32\wbem\WmiPrvSE.exe
CommandLine|contains: C:\Windows\TEMP\
CommandLine|endswith: .mof

filter_main_installutil

ParentCommandLine|endswith: \InstallUtil.exe /Uninstall C:\Windows\CCM\Microsoft.ConfigurationManager.SVProvider.dll
ParentImage|endswith: \InstallUtil.exe
CommandLine|contains|all:
  - C:\Windows\TEMP
  - .tmp

filter_optional_null_parent

ParentCommandLine: null

Condition

all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*

Raw YAML

title: Potentially Suspicious Mofcomp Execution
id: 1dd05363-104e-4b4a-b963-196a534b03a1
status: test
description: |
    Detects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline.
    The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository.
    Attackers abuse this utility to install malicious MOF scripts
references:
    - https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
    - https://github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/win_mofcomp_execution.yml
    - https://learn.microsoft.com/en-us/windows/win32/wmisdk/mofcomp
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-07-12
modified: 2026-08-06
tags:
    - attack.stealth
    - attack.t1218
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\mofcomp.exe'
        - OriginalFileName: 'mofcomp.exe'
    selection_case:
        - ParentImage|endswith:
              - '\cmd.exe'
              - '\powershell.exe'
              - '\pwsh.exe'
              - '\wsl.exe'
              - '\wscript.exe'
              - '\cscript.exe'
        - CommandLine|contains:
              - '\AppData\Local\Temp'
              - '\Contacts\'
              - '\Favorites\'
              - '\Favourites\'
              - '\Music\'
              - '\Pictures\'
              - '\Users\Public\'
              - '\Videos\'
              - '\WINDOWS\Temp\'
              - '%appdata%'
              - '%temp%'
              - '%tmp%'
    filter_main_wmiprvse:
        ParentImage: 'C:\Windows\System32\wbem\WmiPrvSE.exe'
        CommandLine|contains: 'C:\Windows\TEMP\'
        CommandLine|endswith: '.mof'
    filter_main_installutil:
        ParentCommandLine|endswith: '\InstallUtil.exe /Uninstall C:\Windows\CCM\Microsoft.ConfigurationManager.SVProvider.dll'
        ParentImage|endswith: '\InstallUtil.exe'
        CommandLine|contains|all:
            - 'C:\Windows\TEMP'
            - '.tmp'
    filter_optional_null_parent:
        ParentCommandLine: null
    condition: all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
    - Unknown
level: high

False positives

  • Unknown

References

Similar rules