Analytics BIOC Informational

Linux process execution with a rare GitHub URL

A process was executed with an uncommon GitHub URL in its command line. This may have legitimate uses, but it might also be used by attackers to download malicious payloads.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter (T1059)
Attacker's goals:

Download a second stage payload for execution.

Investigative actions:

Check if the initiator process is malicious. Check the user activity on the same agent at that time. Check if the host is a development server. Check if this installation was related to more installations at the same time. Check for additional file/network operations by the same process instance.

Test period:
N/A (single event)
Deduplication:
3 Hours