Apache Spark Shell Command Injection - ProcessCreation

 Original Source: [Sigma source]
Title: Apache Spark Shell Command Injection - ProcessCreation
Status: test
Description:Detects attempts to exploit an apache spark server via CVE-2014-6287 from a commandline perspective
References:
  -https://github.com/W01fh4cker/cve-2022-33891/blob/fd973b56e78bca8822caa3a2e3cf1b5aff5d0950/cve_2022_33891_poc.py
  -https://sumsec.me/2022/CVE-2022-33891%20Apache%20Spark%20shell%20command%20injection.html
  -https://github.com/apache/spark/pull/36315/files
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-07-20
modified:None
Tags:
  • -'attack.initial-access'
  • -'attack.t1190'
  • -'cve.2022-33891'
Logsource:
  • product: linux
  • category: process_creation
Detection:
  selection:
    ParentImage|endswith: '\bash'
    CommandLine|contains:
      -'id -Gn `'
      -'id -Gn ''

  condition:selection
Falsepositives:
  -Unlikely
Level: high