This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Command Line Execution with Suspicious URL and AppData Strings
Original Source:
[Sigma source]
Title:
Command Line Execution with Suspicious URL and AppData Strings
Status:
test
Description:
Detects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)
References:
-https://www.hybrid-analysis.com/sample/3a1f01206684410dbe8f1900bbeaaa543adfcd07368ba646b499fa5274b9edf6?environmentId=100
-https://www.hybrid-analysis.com/sample/f16c729aad5c74f19784a24257236a8bbe27f7cdc4a89806031ec7f1bebbd475?environmentId=100
Author:
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Date:
2019-01-16
modified:
2021-11-27
Tags:
-'attack.execution'
-'attack.command-and-control'
-'attack.t1059.003'
-'attack.t1059.001'
-'attack.t1105'
Logsource:
category: process_creation
product: windows
Detection:
selection:
Image|endswith
:
'\cmd.exe'
CommandLine|contains|all
:
-'http'
-'://'
-'%AppData%'
condition
:
selection
Falsepositives:
-High
Level:
medium