Elastic Defend high stable eql

Shlayer Malware Infection

Identifies the execution of curl to download a payload for execution. This behavior is consistent with Shlayer malware. Shlayer is a macOS malware family associated with ad fraud activity. Shlayer masquerades typically as an installer for applications like Adobe Flash Player and executes numerous macOS commands to deobfuscate code and install adware with persistence mechanisms.

View Source

Detection Logic

process where event.action == "exec" and process.name in ("curl", "nscurl") and process.args like "-f0L"

Field Validations

Loading…

Comments (0)

Loading comments...