Unsigned or Untrusted Binary Execution via Zshrc
Description
Detects the execution of an unsigned or untrusted binary via the Zsh shell startup file .zshrc. Threat actors can modify the .zshrc file with the path to their payload in order to persist on a victims system. When the host reboots the payload will be executed and this is the activity you will see. A recent DPRK payload, ThiefBucket, implements this persistence mechanism.
Query · eql
sequence with maxspan=15s
[process where event.type == "start" and event.action == "exec" and process.name == "zsh" and process.args like~ "-zsh" and
process.parent.name == "login"] by process.entity_id
[process where event.type == "start" and event.action == "exec" and process.parent.name == "zsh" and
process.executable like "/Users/*" and (process.code_signature.trusted == false or process.code_signature.exists == false) and
process.args_count == 1] by process.parent.entity_id
[network where event.type == "start" and
not cidrmatch(destination.ip,
"240.0.0.0/4", "233.252.0.0/24", "224.0.0.0/4", "198.19.0.0/16", "192.18.0.0/15",
"192.0.0.0/24", "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12",
"192.0.2.0/24", "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24",
"100.64.0.0/10", "192.175.48.0/24", "198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24",
"::1", "FE80::/10", "FF00::/8")] by process.parent.entity_id