PowerShell Base64 Encoded Invoke Keyword

 Original Source: [Sigma source]
Title: PowerShell Base64 Encoded Invoke Keyword
Status: test
Description:Detects UTF-8 and UTF-16 Base64 encoded powershell 'Invoke-' calls
References:
  -https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/
Author: pH-T (Nextron Systems), Harjot Singh, @cyb3rjy0t
Date: 2022-05-20
modified:2023-04-06
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059.001'
  • -'attack.t1027'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    - Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
    - OriginalFileName:
      - 'PowerShell.EXE'
      - 'pwsh.dll'
  selection_cli_enc:
    CommandLine|contains: ' -e'
  selection_cli_invoke:
    CommandLine|contains:
      -'SQBuAHYAbwBrAGUALQ'
      -'kAbgB2AG8AawBlAC0A'
      -'JAG4AdgBvAGsAZQAtA'
      -'SW52b2tlL'
      -'ludm9rZS'
      -'JbnZva2Ut'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high