Linux Base64 Encoded Shebang In CLI

 Original Source: [Sigma source]
Title: Linux Base64 Encoded Shebang In CLI
Status: test
Description:Detects the presence of a base64 version of the shebang in the commandline, which could indicate a malicious payload about to be decoded
References:
  -https://www.trendmicro.com/pl_pl/research/20/i/the-evolution-of-malicious-shell-scripts.html
  -https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-15
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1140'
Logsource:
  • product: linux
  • category: process_creation
Detection:
  selection:
    CommandLine|contains:
      -'IyEvYmluL2Jhc2'
      -'IyEvYmluL2Rhc2'
      -'IyEvYmluL3pza'
      -'IyEvYmluL2Zpc2'
      -'IyEvYmluL3No'

  condition:selection
Falsepositives:
  -Legitimate administration activities
Level: medium