Title:Suspicious Greedy Compression Using Rar.EXE Status:test Description:Detects RAR usage that creates an archive from a suspicious folder, either a system folder or one of the folders often used by attackers for staging purposes References: -https://decoded.avast.io/martinchlumecky/png-steganography Author: X__Junior (Nextron Systems), Florian Roth (Nextron Systems) Date: 2022-12-15 modified:2024-01-02 Tags:
-'attack.execution'
-'attack.t1059'
Logsource:
product: windows
category: process_creation
Detection: selection_opt_1: Image|endswith:'\rar.exe'Description:'Command line RAR'selection_opt_2: CommandLine|contains: -'.exe a ' -' a -m'