Suspicious FromBase64String Usage On Gzip Archive - Ps Script

 Original Source: [Sigma source]
Title: Suspicious FromBase64String Usage On Gzip Archive - Ps Script
Status: test
Description:Detects attempts of decoding a base64 Gzip archive in a PowerShell script. This technique is often used as a method to load malicious content into memory afterward.
References:
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=43
Author: frack113
Date: 2022-12-23
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.t1132.001'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'FromBase64String'
      -'MemoryStream'
      -'H4sI'

  condition:selection
Falsepositives:
  -Legitimate administrative script
Level: medium