Suspicious PowerShell Download and Execute Pattern

 Original Source: [Sigma source]
Title: Suspicious PowerShell Download and Execute Pattern
Status: test
Description:Detects suspicious PowerShell download patterns that are often used in malicious scripts, stagers or downloaders (make sure that your backend applies the strings case-insensitive)
References:
  -https://gist.github.com/jivoi/c354eaaf3019352ce32522f916c03d70
  -https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html
Author: Florian Roth (Nextron Systems)
Date: 2022-02-28
modified:2022-03-01
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains:
      -'IEX ((New-Object Net.WebClient).DownloadString'
      -'IEX (New-Object Net.WebClient).DownloadString'
      -'IEX((New-Object Net.WebClient).DownloadString'
      -'IEX(New-Object Net.WebClient).DownloadString'
      -' -command (New-Object System.Net.WebClient).DownloadFile('
      -' -c (New-Object System.Net.WebClient).DownloadFile('

  condition:selection
Falsepositives:
  -Software installers that pull packages from remote systems and execute them
Level: high