Arbitrary File Download Via Squirrel.EXE

 Original Source: [Sigma source]
Title: Arbitrary File Download Via Squirrel.EXE
Status: test
Description:Detects the usage of the "Squirrel.exe" to download arbitrary files. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
References:
  -https://lolbas-project.github.io/lolbas/OtherMSBinaries/Squirrel/
  -http://www.hexacorn.com/blog/2019/03/30/sqirrel-packages-manager-as-a-lolbin-a-k-a-many-electron-apps-are-lolbins-by-default/
  -http://www.hexacorn.com/blog/2018/08/16/squirrel-as-a-lolbin/
Author: Nasreddine Bencherchali (Nextron Systems), Karneades / Markus Neis, Jonhnathan Ribeiro, oscd.community
Date: 2022-06-09
modified:2023-11-09
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    Image|endswith:
      -'\squirrel.exe'
      -'\update.exe'

  selection_download_cli:
    CommandLine|contains:
      -' --download '
      -' --update '
      -' --updateRollback='

  selection_download_http_keyword:
    CommandLine|contains: 'http'
  condition:all of selection_*
Falsepositives:
  -Expected FP with some Electron based applications such as (1Clipboard, Beaker Browser, Caret, Discord, GitHub Desktop, etc.)
Level: medium