BIOC Informational

Shell binary copied to another location

Attackers may try to evade detection by copying the shell binary to an innocent-looking name.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Masquerading (T1036)
Indicator:

Process action type = execution AND target process cmd =~ /bin/(ba|z|fi|tc|c|k)?sh AND target process name = cp

Preventable: yes