Linux grep file discovery targeting GobRAT-specific filenames
Alerts on grep executions on Linux whose arguments contain specific malware-related file names for discovery.
- Product
- linux
- Category
- process_creation
- Author
- Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
- Published
- 2023-06-02
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies Linux process executions of /grep where the command line contains filenames associated with potential GobRAT activity (apached, frpc, sshd.sh, zone.arm). Attackers often use grep to quickly enumerate or confirm the presence of specific files during staging and discovery. The detection relies on process creation telemetry, specifically the executed image path ending in /grep and matching substrings within the command line.
Reporting behind it
- blogs.jpcert.or.jphttps://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- virustotal.comhttps://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- virustotal.comhttps://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_malware_gobrat_grep_payload_discovery.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux grep file discovery targeting GobRAT-specific filenames
id: 57842cca-b388-4e69-9b43-76fb4584a429
status: test
description: This rule identifies Linux process executions of /grep where the command line contains filenames associated with potential GobRAT activity (apached, frpc, sshd.sh, zone.arm). Attackers often use grep to quickly enumerate or confirm the presence of specific files during staging and discovery. The detection relies on process creation telemetry, specifically the executed image path ending in /grep and matching substrings within the command line.
references:
- https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_malware_gobrat_grep_payload_discovery.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2023-06-02
tags:
- attack.discovery
- attack.t1082
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: /grep
CommandLine|contains:
- apached
- frpc
- sshd.sh
- zone.arm
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: e34cfa0c-0a50-4210-9cb3-5632d08eb041
type: derived