Potential Multi Architecture File Downloads
Description
Identifies the execution of curl, wget or ftpg to download payloads named by architecture type in preparation for execution. This behavior is consistent with Mirai bot deployment shell scripts.
Query · eql
sequence by process.parent.entity_id with maxspan=5s
[process where event.type == "start" and event.action == "exec" and process.name in ("curl", "wget", "ftpg") and
process.args like~ (
"http*mipsel", "http*i686", "http*sparc", "http*mips", "http*sh4","http*x86", "http*armv6l", "http*powerpc",
"http*i586", "http*m68k", "http*armv4l", "http*armv5l", "http*mpsl", "http*arm4", "http*arm5", "http*arm6",
"http*arm7", "http*ppc"
)]
[process where event.type == "start" and event.action == "exec" and process.name in ("curl", "wget", "ftpg") and
process.args like~ (
"http*mipsel", "http*i686", "http*sparc", "http*mips", "http*sh4","http*x86", "http*armv6l", "http*powerpc",
"http*i586", "http*m68k", "http*armv4l", "http*armv5l", "http*mpsl", "http*arm4", "http*arm5", "http*arm6",
"http*arm7", "http*ppc"
)]
[process where event.type == "start" and event.action == "exec" and process.name in ("curl", "wget", "ftpg") and
process.args like~ (
"http*mipsel", "http*i686", "http*sparc", "http*mips", "http*sh4","http*x86", "http*armv6l", "http*powerpc",
"http*i586", "http*m68k", "http*armv4l", "http*armv5l", "http*mpsl", "http*arm4", "http*arm5", "http*arm6",
"http*arm7", "http*ppc"
)]