Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
Detects the execution of concatenated commands via "cmd.exe". Pikabot often executes a combination of multiple commands via the command handler "cmd /c" in order to download and execute additional payloads. Commands such as "curl", "wget" in order to download extra payloads. "ping" and "timeout" are abused to introduce delays in the command execution and "Rundll32" is also used to execute malicious DLL files. In the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.
Detection logic
selection_cmd
CommandLine|contains|all:
- cmd
- /cselection_pipes
CommandLine|contains:
- " & "
- " || "selection_commands_1
CommandLine|contains:
- " curl"
- " wget"
- " timeout "
- " ping "selection_commands_2
CommandLine|contains:
- " rundll32"
- " mkdir "Condition
all of selection_*Raw YAML
title: Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
id: e5144106-8198-4f6e-bfc2-0a551cc8dd94
status: test
description: |
Detects the execution of concatenated commands via "cmd.exe". Pikabot often executes a combination of multiple commands via the command handler "cmd /c" in order to download and execute additional payloads.
Commands such as "curl", "wget" in order to download extra payloads. "ping" and "timeout" are abused to introduce delays in the command execution and "Rundll32" is also used to execute malicious DLL files.
In the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.
references:
- https://github.com/pr0xylife/Pikabot/blob/7f7723a74ca325ec54c6e61e076acce9a4b20538/Pikabot_30.10.2023.txt
- https://github.com/pr0xylife/Pikabot/blob/7f7723a74ca325ec54c6e61e076acce9a4b20538/Pikabot_22.12.2023.txt
author: Alejandro Houspanossian ('@lekz86')
date: 2024-01-02
tags:
- attack.command-and-control
- attack.execution
- attack.stealth
- attack.t1059.003
- attack.t1105
- attack.t1218
- detection.emerging-threats
logsource:
product: windows
category: process_creation
detection:
selection_cmd:
CommandLine|contains|all:
- 'cmd'
- '/c'
selection_pipes:
CommandLine|contains:
- ' & '
- ' || '
selection_commands_1:
CommandLine|contains:
- ' curl'
- ' wget'
- ' timeout '
- ' ping '
selection_commands_2:
CommandLine|contains:
- ' rundll32'
- ' mkdir '
condition: all of selection_*
falsepositives:
- Unknown
level: mediumFalse positives
- Unknown
References
Similar rules
PowerShell MSI Install via WindowsInstaller COM From Remote Location
mediumwindows · Shares T1059, T1218, T1105
Potential Exploitation of RCE Vulnerability CVE-2025-33053
highwindows · Shares T1218, T1105
Axios NPM Compromise Indicators - Windows
highwindows · Shares T1059, T1105
Greenbug Espionage Group Indicators
criticalwindows · Shares T1059, T1105