Linux grep file discovery targeting GobRAT-specific filenames

Alerts on grep executions on Linux whose arguments contain specific malware-related file names for discovery.

FreeReviewedSigma · High · v2
Product
linux
Category
process_creation
Author
Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
Published
2023-06-02
Updated
2026-07-31
title: Linux grep file discovery targeting GobRAT-specific filenames
id: 57842cca-b388-4e69-9b43-76fb4584a429
status: test
description: This rule identifies Linux process executions of /grep where the command line contains filenames associated with potential GobRAT activity (apached, frpc, sshd.sh, zone.arm). Attackers often use grep to quickly enumerate or confirm the presence of specific files during staging and discovery. The detection relies on process creation telemetry, specifically the executed image path ending in /grep and matching substrings within the command line.
references:
  - https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
  - https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
  - https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_malware_gobrat_grep_payload_discovery.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2023-06-02
tags:
  - attack.discovery
  - attack.t1082
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    Image|endswith: /grep
    CommandLine|contains:
      - apached
      - frpc
      - sshd.sh
      - zone.arm
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: e34cfa0c-0a50-4210-9cb3-5632d08eb041
    type: derived