Potential In-Memory Download And Compile Of Payloads

 Original Source: [Sigma source]
Title: Potential In-Memory Download And Compile Of Payloads
Status: test
Description:Detects potential in-memory downloading and compiling of applets using curl and osacompile as seen used by XCSSET malware
References:
  -https://redcanary.com/blog/mac-application-bundles/
Author: Sohan G (D4rkCiph3r), Red Canary (idea)
Date: 2023-08-22
modified:None
Tags:
  • -'attack.command-and-control'
  • -'attack.execution'
  • -'attack.t1059.007'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: macos
Detection:
  selection:
    CommandLine|contains|all:
      -'osacompile'
      -'curl'

  condition:selection
Falsepositives:
  -Unknown
Level: medium