Password Protected ZIP File Opened (Suspicious Filenames)
Detects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.
Detection logic
selection
EventID: 5379
TargetName|contains: Microsoft_Windows_Shell_ZipFolder:filenameselection_filename
TargetName|contains:
- invoice
- new order
- rechnung
- factura
- delivery
- purchase
- order
- paymentCondition
selection and selection_filenameRaw YAML
title: Password Protected ZIP File Opened (Suspicious Filenames)
id: 54f0434b-726f-48a1-b2aa-067df14516e4
status: test
description: Detects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.
references:
- https://twitter.com/sbousseaden/status/1523383197513379841
author: Florian Roth (Nextron Systems)
date: 2022-05-09
tags:
- attack.command-and-control
- attack.stealth
- attack.t1027
- attack.t1105
- attack.t1036
logsource:
product: windows
service: security
detection:
selection:
EventID: 5379
TargetName|contains: 'Microsoft_Windows_Shell_ZipFolder:filename'
selection_filename:
TargetName|contains:
- 'invoice'
- 'new order'
- 'rechnung'
- 'factura'
- 'delivery'
- 'purchase'
- 'order'
- 'payment'
condition: selection and selection_filename
falsepositives:
- Legitimate used of encrypted ZIP files
level: highFalse positives
- Legitimate used of encrypted ZIP files
References
Similar rules
Suspicious Download Via Certutil.EXE
mediumwindows · Shares T1027, T1105
Suspicious File Downloaded From Direct IP Via Certutil.EXE
highwindows · Shares T1027, T1105
Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
highwindows · Shares T1027, T1105
File Download Via Bitsadmin
mediumwindows · Shares T1036, T1105