Title:
Scheduled Task Creation with Curl and PowerShell Execution Combo
Status:
experimental
Description:Detects the creation of a scheduled task using schtasks.exe, potentially in combination with curl for downloading payloads and PowerShell for executing them.
This facilitates executing malicious payloads or connecting with C&C server persistently without dropping the malware sample on the host.
References:
-https://tria.ge/241015-l98snsyeje/behavioral2
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
Date: 2025-02-05
modified:None
Tags:
- -'attack.privilege-escalation'
- -'attack.execution'
- -'attack.persistence'
- -'attack.stealth'
- -'attack.t1053.005'
- -'attack.t1218'
- -'attack.command-and-control'
- -'attack.t1105'
Logsource:
- category: process_creation
- product: windows
Detection:
selection_img:
Image|endswith:
'\schtasks.exe'
CommandLine|contains|windash:
' /create '
selection_curl:
CommandLine|contains|all:
-'curl '
-'http'
-'-o'
selection_powershell:
CommandLine|contains:
'powershell'
condition:
all of selection_*
Falsepositives:
-Legitimate use of schtasks for administrative purposes.
-Automation scripts combining curl and PowerShell in controlled environments.
Level:
medium