Elastic Defend high stable eql

Egress Connection by a YUM Package Manager Descendant

Detects suspicious network events executed by the Yum package manager, potentially indicating persistence through a Yum backdoor. In Linux, Yum (Yellowdog Updater, Modified) is a command-line utility used for handling packages on Fedora-based systems, providing functions for installing, updating, upgrading, and removing software along with managing package repositories. Attackers can backdoor Yum to gain persistence by injecting malicious code into plugins that Yum runs, thereby ensuring continued unauthorized access or control each time Yum is used for package management. For this persistence mechanism to work, plugins need to be enabled in the `/etc/dnf/dnf.conf` and plugin.conf files.

View Source

Detection Logic

sequence by process.entity_id with maxspan=5s
  [process where event.type == "start" and event.action == "exec" and (
   process.name : (
     "bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "python*", "php*",
     "perl", "ruby", "lua*", "openssl", "nc", "ncat", "netcat", "netcat.openbsd",
     "netcat.traditional", "nc.openbsd", "nc.traditional", "telnet", "awk"
   ) or
   process.executable : (
     "./*", "/boot/*", "/dev/shm/*", "/etc/cron.*/*", "/etc/init.d/*", "/etc/update-motd.d/*", "/run/*", "/srv/*",
     "/tmp/*", "/var/tmp/*", "/var/log/*"
     )
   ) and descendant of [process where event.action == "exec" and process.name == "yum"] and not (
     process.executable : "/run/user/*/newroot/*" or
     process.args : "/usr/local/cpanel/*"
   )
  ]
  [network where event.action == "connection_attempted" and event.type == "start" and not (
     destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
       destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
       "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
       "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
       "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
       "FF00::/8", "172.31.0.0/16"
       ) or
     process.name in ("yumBackend.py", "urlgrabber-ext-down") or
     process.executable in ("/usr/share/logstash/jdk/bin/java", "/opt/java/openjdk/bin/java", "/usr/local/cpanel/scripts/rebuildhttpdconf")
     )
  ]

Field Validations

Loading…

Comments (0)

Loading comments...