BIOC
Informational
✕
Scripting engine creates a compressed file under a suspicious folder
Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Collection
- Status:
- Enabled
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data Staged (T1074)
Indicator:
File file name = *.rar , *.7z , *.tar , *.gz , *.zip , *.zz , *.s7z , *.cab AND file path = *users\*\appdata\* , *\programdata* , *$recycle.bin* , *\temp\* AND action type = create Process initiated by = powershell.exe , wscript.exe , cscript.exe , mshta.exe , regsvr32.exe , cgo name = powershell.exe , wscript.exe , cscript.exe , mshta.exe , regsvr32.exe
Preventable: yes