Potential PowerShell Obfuscation Via Reversed Commands

 Original Source: [Sigma source]
Title: Potential PowerShell Obfuscation Via Reversed Commands
Status: test
Description:Detects the presence of reversed PowerShell commands in the CommandLine. This is often used as a method of obfuscation by attackers
References:
  -https://2019.offzone.moscow/ru/report/hunting-for-powershell-abuses/
  -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=66
Author: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton
Date: 2020-10-11
modified:2023-05-31
Tags:
  • -'attack.stealth'
  • -'attack.t1027'
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli:
    CommandLine|contains:
      -'hctac'
      -'kaerb'
      -'dnammoc'
      -'ekovn'
      -'eliFd'
      -'rahc'
      -'etirw'
      -'golon'
      -'tninon'
      -'eddih'
      -'tpircS'
      -'ssecorp'
      -'llehsrewop'
      -'esnopser'
      -'daolnwod'
      -'tneilCbeW'
      -'tneilc'
      -'ptth'
      -'elifotevas'
      -'46esab'
      -'htaPpmeTteG'
      -'tcejbO'
      -'maerts'
      -'hcaerof'
      -'retupmoc'

  filter_main_encoded_keyword:
    CommandLine|contains:
      -' -EncodedCommand '
      -' -enc '

  condition:all of selection_* and not 1 of filter_main_*
Falsepositives:
  -Unlikely
Level: high