Suspicious Deno File Written from Remote Source
Detects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL. This behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.
Detection logic
selection_path
TargetFilename|contains:
- \deno\gen\
- \deno\remote\https\
TargetFilename|contains|all:
- :\Users\
- \AppData\Condition
selection_pathRaw YAML
title: Suspicious Deno File Written from Remote Source
id: 6c0ce3b6-85e2-49d4-9c3f-6e008ce9796e
status: experimental
description: |
Detects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL.
This behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.
references:
- https://taggart-tech.com/evildeno/
author: Josh Nickels, Michael Taggart
date: 2025-05-22
tags:
- attack.execution
- attack.t1204
- attack.t1059.007
- attack.command-and-control
- attack.t1105
logsource:
category: file_event
product: windows
detection:
selection_path:
TargetFilename|contains:
- '\deno\gen\'
- '\deno\remote\https\'
TargetFilename|contains|all:
- ':\Users\'
- '\AppData\'
condition: selection_path
falsepositives:
- Legitimate usage of deno to request a file or bring a DLL to a host
level: lowFalse positives
- Legitimate usage of deno to request a file or bring a DLL to a host
References
Similar rules
DarkGate - Autoit3.EXE File Creation By Uncommon Process
mediumwindows · Shares T1105, T1059
Axios NPM Compromise Indicators - Windows
highwindows · Shares T1059, T1105
Command Line Execution with Suspicious URL and AppData Strings
mediumwindows · Shares T1059, T1105
Greenbug Espionage Group Indicators
criticalwindows · Shares T1059, T1105