Gzip Archive Decode Via PowerShell
Detects attempts of decoding encoded Gzip archives via PowerShell.
Detection logic
selection
CommandLine|contains|all:
- GZipStream
- ::DecompressCondition
selectionRaw YAML
title: Gzip Archive Decode Via PowerShell
id: 98767d61-b2e8-4d71-b661-e36783ee24c1
status: test
description: Detects attempts of decoding encoded Gzip archives via PowerShell.
references:
- https://www.zscaler.com/blogs/security-research/onenote-growing-threat-malware-distribution
author: Hieu Tran
date: 2023-03-13
tags:
- attack.command-and-control
- attack.t1132.001
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains|all:
- 'GZipStream'
- '::Decompress'
condition: selection
falsepositives:
- Legitimate administrative scripts may use this functionality. Use "ParentImage" in combination with the script names and allowed users and applications to filter legitimate executions
level: mediumFalse positives
- Legitimate administrative scripts may use this functionality. Use "ParentImage" in combination with the script names and allowed users and applications to filter legitimate executions
References
Similar rules
DNS Exfiltration and Tunneling Tools Execution
highwindows · Shares T1132
Suspicious FromBase64String Usage On Gzip Archive - Process Creation
mediumwindows · Shares T1132
Suspicious FromBase64String Usage On Gzip Archive - Ps Script
mediumwindows · Shares T1132
Arbitrary File Download Via GfxDownloadWrapper.EXE
mediumwindows · Same logsource category (process_creation)