BIOC Informational

Scripting engine creates a compressed file under a suspicious folder

Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity.

Module:
Platform Analytics
Agent event type:
File
Category:
Collection
Status:
Enabled
ATT&CK tactics: Collection (TA0009)
ATT&CK techniques: Data Staged (T1074)
Indicator:

File file name = *.rar , *.7z , *.tar , *.gz , *.zip , *.zz , *.s7z , *.cab AND file path = *users\*\appdata\* , *\programdata* , *$recycle.bin* , *\temp\* AND action type = create Process initiated by = powershell.exe , wscript.exe , cscript.exe , mshta.exe , regsvr32.exe , cgo name = powershell.exe , wscript.exe , cscript.exe , mshta.exe , regsvr32.exe

Preventable: yes