Detection rules › Elastic

Egress Connection by a YUM Package Manager Descendant

Time window
5s
Sequence by
process.entity_id
Source
github.com/elastic/protections-artifacts

Detects suspicious network events executed by the Yum package manager, potentially indicating persistence through a Yum backdoor. In Linux, Yum (Yellowdog Updater, Modified) is a command-line utility used for handling packages on Fedora-based systems, providing functions for installing, updating, upgrading, and removing software along with managing package repositories. Attackers can backdoor Yum to gain persistence by injecting malicious code into plugins that Yum runs, thereby ensuring continued unauthorized access or control each time Yum is used for package management. For this persistence mechanism to work, plugins need to be enabled in the /etc/dnf/dnf.conf and plugin.conf files.

MITRE ATT&CK coverage

Rule body

[rule]
description = """
Detects suspicious network events executed by the Yum package manager, potentially indicating persistence through a Yum
backdoor. In Linux, Yum (Yellowdog Updater, Modified) is a command-line utility used for handling packages on
Fedora-based systems, providing functions for installing, updating, upgrading, and removing software along with managing
package repositories. Attackers can backdoor Yum to gain persistence by injecting malicious code into plugins that Yum
runs, thereby ensuring continued unauthorized access or control each time Yum is used for package management. For this
persistence mechanism to work, plugins need to be enabled in the `/etc/dnf/dnf.conf` and plugin.conf files.
"""
id = "74afd5bc-7d44-4a11-9383-a5e30c3ec8ae"
license = "Elastic License v2"
name = "Egress Connection by a YUM Package Manager Descendant"
os_list = ["linux"]
reference = [
    "https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/yum_package_manager_persistence.rb",
    "https://www.elastic.co/security-labs/sequel-on-persistence-mechanisms",
]
version = "1.0.8"

query = '''
sequence by process.entity_id with maxspan=5s
  [process where event.type == "start" and event.action == "exec" and (
   process.name : (
     "bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "python*", "php*",
     "perl", "ruby", "lua*", "openssl", "nc", "ncat", "netcat", "netcat.openbsd",
     "netcat.traditional", "nc.openbsd", "nc.traditional", "telnet", "awk"
   ) or
   process.executable : (
     "./*", "/boot/*", "/dev/shm/*", "/etc/cron.*/*", "/etc/init.d/*", "/etc/update-motd.d/*", "/run/*", "/srv/*",
     "/tmp/*", "/var/tmp/*", "/var/log/*"
     )
   ) and descendant of [process where event.action == "exec" and process.name == "yum"] and not (
     process.executable : "/run/user/*/newroot/*" or
     process.args : "/usr/local/cpanel/*"
   )
  ]
  [network where event.action == "connection_attempted" and event.type == "start" and not (
     destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
       destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
       "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
       "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
       "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
       "FF00::/8", "172.31.0.0/16"
       ) or
     process.name in ("yumBackend.py", "urlgrabber-ext-down") or
     process.executable in ("/usr/share/logstash/jdk/bin/java", "/opt/java/openjdk/bin/java", "/usr/local/cpanel/scripts/rebuildhttpdconf")
     )
  ]
'''

min_endpoint_version = "7.15.0"
optional_actions = []
[[actions]]
action = "kill_process"
field = "process.entity_id"
state = 1

[[threat]]
framework = "MITRE ATT&CK"
[[threat.technique]]
id = "T1543"
name = "Create or Modify System Process"
reference = "https://attack.mitre.org/techniques/T1543/"

[[threat.technique]]
id = "T1574"
name = "Hijack Execution Flow"
reference = "https://attack.mitre.org/techniques/T1574/"


[threat.tactic]
id = "TA0003"
name = "Persistence"
reference = "https://attack.mitre.org/tactics/TA0003/"
[[threat]]
framework = "MITRE ATT&CK"

[threat.tactic]
id = "TA0005"
name = "Defense Evasion"
reference = "https://attack.mitre.org/tactics/TA0005/"
[[threat]]
framework = "MITRE ATT&CK"

[threat.tactic]
id = "TA0011"
name = "Command and Control"
reference = "https://attack.mitre.org/tactics/TA0011/"

[internal]
min_endpoint_version = "7.15.0"

Stages and Predicates

Ordered sequence: each step below must occur in order within 5s, correlated by process.entity_id.

Stage 1: process

[process where event.type == "start" and event.action == "exec" and (
   process.name : (
     "bash", "dash", "sh", "tcsh", "csh", "zsh", "ksh", "fish", "python*", "php*",
     "perl", "ruby", "lua*", "openssl", "nc", "ncat", "netcat", "netcat.openbsd",
     "netcat.traditional", "nc.openbsd", "nc.traditional", "telnet", "awk"
   ) or
   process.executable : (
     "./*", "/boot/*", "/dev/shm/*", "/etc/cron.*/*", "/etc/init.d/*", "/etc/update-motd.d/*", "/run/*", "/srv/*",
     "/tmp/*", "/var/tmp/*", "/var/log/*"
     )
   ) and descendant of [process where event.action == "exec" and process.name == "yum"] and not (
     process.executable : "/run/user/*/newroot/*" or
     process.args : "/usr/local/cpanel/*"
   )
  ]

Stage 2: network

[network where event.action == "connection_attempted" and event.type == "start" and not (
     destination.ip == null or destination.ip == "0.0.0.0" or cidrmatch(
       destination.ip, "10.0.0.0/8", "127.0.0.0/8", "169.254.0.0/16", "172.16.0.0/12", "192.0.0.0/24", "192.0.0.0/29",
       "192.0.0.8/32", "192.0.0.9/32", "192.0.0.10/32", "192.0.0.170/32", "192.0.0.171/32", "192.0.2.0/24",
       "192.31.196.0/24", "192.52.193.0/24", "192.168.0.0/16", "192.88.99.0/24", "224.0.0.0/4", "100.64.0.0/10",
       "192.175.48.0/24","198.18.0.0/15", "198.51.100.0/24", "203.0.113.0/24", "240.0.0.0/4", "::1", "FE80::/10",
       "FF00::/8", "172.31.0.0/16"
       ) or
     process.name in ("yumBackend.py", "urlgrabber-ext-down") or
     process.executable in ("/usr/share/logstash/jdk/bin/java", "/opt/java/openjdk/bin/java", "/usr/local/cpanel/scripts/rebuildhttpdconf")
     )
  ]

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
process.argsstarts_with/usr/local/cpanel/excludes:process.args field:"process.args" value:"/usr/local/cpanel/"
process.executablewildcard/run/user/*/newroot/*excludes:process.executable field:"process.executable" value:"/run/user/*/newroot/*"
destination.ipcidr_match10.0.0.0/8, 127.0.0.0/8, 169.254.0.0/16, 172.16.0.0/12, 192.0.0.0/24, 192.0.0.0/29, 192.0.0.8/32, 192.0.0.9/32, 192.0.0.10/32, 192.0.0.170/32, 192.0.0.171/32, 192.0.2.0/24, 192.31.196.0/24, 192.52.193.0/24, 192.168.0.0/16, 192.88.99.0/24, 224.0.0.0/4, 100.64.0.0/10, 192.175.48.0/24, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24, 240.0.0.0/4, ::1, FE80::/10, FF00::/8, 172.31.0.0/16excludes:destination.ip
destination.ipeq0.0.0.0excludes:destination.ip field:"destination.ip" value:"0.0.0.0"
destination.ipis_null(no value, null check)excludes:destination.ip
process.executablein/opt/java/openjdk/bin/java, /usr/local/cpanel/scripts/rebuildhttpdconf, /usr/share/logstash/jdk/bin/javaexcludes:process.executable field:"process.executable" value:"/opt/java/openjdk/bin/java" field:"process.executable" value:"/usr/local/cpanel/scripts/rebuildhttpdconf" field:"process.executable" value:"/usr/share/logstash/jdk/bin/java"
process.nameinurlgrabber-ext-down, yumBackend.pyexcludes:process.name field:"process.name" value:"urlgrabber-ext-down" field:"process.name" value:"yumBackend.py"

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
event.actioneq
  • connection_attempted
  • exec
field:"EventType" kind:eq
event.typeeq
  • start
field:"event.type" kind:eq value:"start"
process.executablewildcard
  • ./*
  • /boot/*
  • /dev/shm/*
  • /etc/cron.*/*
  • /etc/init.d/*
  • /etc/update-motd.d/*
  • /run/*
  • /srv/*
  • /tmp/*
  • /var/log/*
  • /var/tmp/*
field:"Image" kind:wildcard
process.namewildcard
  • awk
  • bash
  • csh
  • dash
  • fish
  • ksh
  • lua*
  • nc
  • nc.openbsd
  • nc.traditional
  • ncat
  • netcat
  • netcat.openbsd
  • netcat.traditional
  • openssl
  • perl
  • php*
  • python*
  • ruby
  • sh
  • tcsh
  • telnet
  • zsh
field:"process_name" kind:wildcard