Executable File Creation via Base64


Description

Detects when an executable file is created by the base64 system binary. Malware, specifically OceanLotus in this case, can bring along an embedded second stage payload that is base64 encoded. Upon execution the initial access payload decodes this second stage encoded payload and creates a new executable file. This activity is inherently malicious and should not occur normally under any circumstance.

Query · eql

file where event.action == "modification" and process.name == "base64" and file.Ext.header_bytes like~ ("cffaedfe*", "cafebabe*")
Raw source Executable File Creation via Base64 · Elastic TOML
Esc
Published by elastic/protections-artifacts ↗, licensed under Elastic License 2.0 ↗. Reproduced here unmodified.
[rule]
description = """
Detects when an executable file is created by the base64 system binary. Malware, specifically OceanLotus in this case,
can bring along an embedded second stage payload that is base64 encoded. Upon execution the initial access payload
decodes this second stage encoded payload and creates a new executable file. This activity is inherently malicious and
should not occur normally under any circumstance.
"""
id = "9e393ee9-9ac6-4bcc-81ff-515bfd7f6479"
license = "Elastic License v2"
name = "Executable File Creation via Base64"
os_list = ["macos"]
reference = [
    "https://github.com/center-for-threat-informed-defense/adversary_emulation_library/tree/4a57b3dd5d28ad1bd79e927e04b20fd4d66934a0/ocean_lotus",
]
version = "1.0.5"

query = '''
file where event.action == "modification" and process.name == "base64" and file.Ext.header_bytes like~ ("cffaedfe*", "cafebabe*")
'''

min_endpoint_version = "8.11.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "Effective_process.entity_id"
state = 0

[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 0

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1027"
name = "Obfuscated Files or Information"
reference = "https://attack.mitre.org/techniques/T1027/"

[[threat.technique]]
id = "T1140"
name = "Deobfuscate/Decode Files or Information"
reference = "https://attack.mitre.org/techniques/T1140/"


[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"

[internal]
min_endpoint_version = "8.11.0"

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.