Command Line Execution with Suspicious URL and AppData Strings

 Original Source: [Sigma source]
Title: Command Line Execution with Suspicious URL and AppData Strings
Status: test
Description:Detects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)
References:
  -https://www.hybrid-analysis.com/sample/3a1f01206684410dbe8f1900bbeaaa543adfcd07368ba646b499fa5274b9edf6?environmentId=100
  -https://www.hybrid-analysis.com/sample/f16c729aad5c74f19784a24257236a8bbe27f7cdc4a89806031ec7f1bebbd475?environmentId=100
Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
Date: 2019-01-16
modified:2021-11-27
Tags:
  • -'attack.execution'
  • -'attack.command-and-control'
  • -'attack.t1059.003'
  • -'attack.t1059.001'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\cmd.exe'
    CommandLine|contains|all:
      -'http'
      -'://'
      -'%AppData%'

  condition:selection
Falsepositives:
  -High
Level: medium