Malicious PowerShell Base64 Exfiltration to save.php via EKZ Stealer

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-09-22
Updated
2026-09-22

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule detects PowerShell posting data with UploadString to a save.php endpoint, the exfiltration channel used by the EKZ Stealer following Fortinet exploitation. Base64-encoded stolen data including credentials is sent to the attacker web handler. Outbound UploadString calls to a save.php target strongly indicate data theft over the C2 channel.

Related detections9 linkedT1041 — drag to rearrange
Malicious NPM Backdoor C2 Beacon to Injective Telemetry Endpoint via Proxy
Suspicious Infostealer C2 Heartbeat to bot heartbeat Endpoint
Suspicious Exfiltration of Environment File via wget POST
Suspicious Data Exfiltration via curl Multipart Upload to Gate Endpoint
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Malicious Vice Society Directory Crawling Script for Data Exfiltration - Via Ps_script (via ps_script)
Malicious PowerShell Exfiltration to webhook.site Following WSUS Exploitation
Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
Malicious PowerShell Base64 Exfiltration to save.php via EKZ Stealer
Pivot detection · T1041 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.