Suspicious Greedy Compression Using Rar.EXE

 Original Source: [Sigma source]
Title: Suspicious Greedy Compression Using Rar.EXE
Status: test
Description:Detects RAR usage that creates an archive from a suspicious folder, either a system folder or one of the folders often used by attackers for staging purposes
References:
  -https://decoded.avast.io/martinchlumecky/png-steganography
Author: X__Junior (Nextron Systems), Florian Roth (Nextron Systems)
Date: 2022-12-15
modified:2024-01-02
Tags:
  • -'attack.execution'
  • -'attack.t1059'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_opt_1:
Image|endswith:'\rar.exe' Description:'Command line RAR'   selection_opt_2:
    CommandLine|contains:
      -'.exe a '
      -' a -m'

  selection_cli_flags:
    CommandLine|contains|all:
      -' -hp'
      -' -r '

  selection_cli_folders:
    CommandLine|contains:
      -' ?:\\\*.'
      -' ?:\\\\\*.'
      -' ?:\$Recycle.bin\'
      -' ?:\PerfLogs\'
      -' ?:\Temp'
      -' ?:\Users\Public\'
      -' ?:\Windows\'
      -' %public%'

  condition:1 of selection_opt_* and all of selection_cli_*
Falsepositives:
  -Unknown
Level: high