Windows ADS Creation with Zone.Identifier Markers Outside Browser Downloads
Flags suspicious creation of :Zone.Identifier ADS streams (ZoneTransfer/ZoneId=3) on file types outside typical browsers.
FreeUnreviewedSigmamediumv1
windows-ads-creation-with-zone-identifier-markers-outside-browser-downloads-573df571
title: Windows ADS Creation with Zone.Identifier Markers Outside Browser Downloads
id: fb04d0be-226c-4193-a884-681be805aaa4
status: test
description: This rule identifies creation of an Alternate Data Stream (ADS) file that uses ZoneTransfer/ZoneId=3 and targets :Zone.Identifier on filenames matching common executable and script/document extensions. Attackers can use this marker to influence how Windows handles downloaded content and potentially bypass user warning expectations. The detection relies on Windows stream creation telemetry, including stream contents, the target ADS filename, and the creating process image, while excluding several common browser binaries.
references:
- https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/create_stream_hash/create_stream_hash_creation_internet_file.yml
author: frack113, Huntrule Team
date: 2022-10-22
modified: 2023-06-12
tags:
- attack.stealth
logsource:
product: windows
category: create_stream_hash
detection:
selection:
Contents|startswith: "[ZoneTransfer] ZoneId=3"
TargetFilename|endswith: :Zone.Identifier
TargetFilename|contains:
- .exe
- .scr
- .bat
- .cmd
- .docx
- .hta
- .jse
- .lnk
- .pptx
- .ps
- .reg
- .sct
- .vb
- .wsc
- .wsf
- .xlsx
filter_optional_brave:
Image|endswith: \brave.exe
filter_optional_chrome:
Image:
- C:\Program Files\Google\Chrome\Application\chrome.exe
- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
filter_optional_firefox:
Image:
- C:\Program Files\Mozilla Firefox\firefox.exe
- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
filter_optional_ie:
Image:
- C:\Program Files (x86)\Internet Explorer\iexplore.exe
- C:\Program Files\Internet Explorer\iexplore.exe
filter_optional_maxthon:
Image|endswith: \maxthon.exe
filter_optional_edge_1:
- Image|startswith: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\
- Image|endswith: \WindowsApps\MicrosoftEdge.exe
- Image:
- C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
- C:\Program Files\Microsoft\Edge\Application\msedge.exe
filter_optional_edge_2:
Image|startswith:
- C:\Program Files (x86)\Microsoft\EdgeCore\
- C:\Program Files\Microsoft\EdgeCore\
Image|endswith:
- \msedge.exe
- \msedgewebview2.exe
filter_optional_opera:
Image|endswith: \opera.exe
filter_optional_safari:
Image|endswith: \safari.exe
filter_optional_seamonkey:
Image|endswith: \seamonkey.exe
filter_optional_vivaldi:
Image|endswith: \vivaldi.exe
filter_optional_whale:
Image|endswith: \whale.exe
filter_optional_snipping_tool:
Image|startswith: C:\Program Files\WindowsApps\Microsoft.ScreenSketch_
Image|endswith: \SnippingTool\SnippingTool.exe
TargetFilename|startswith: C:\Users\
TargetFilename|contains|all:
- \AppData\Local\Packages\Microsoft.ScreenSketch_
- "\\TempState\\Screenshot "
TargetFilename|endswith: .png:Zone.Identifier
condition: selection and not 1 of filter_optional_*
falsepositives:
- Other legitimate browsers not currently included in the filter (please add them)
- Legitimate downloads via scripting or command-line tools (Investigate to determine if it's legitimate)
level: medium
license: DRL-1.1
related:
- id: 573df571-a223-43bc-846e-3f98da481eca
type: derived
What it detects
This rule identifies creation of an Alternate Data Stream (ADS) file that uses ZoneTransfer/ZoneId=3 and targets :Zone.Identifier on filenames matching common executable and script/document extensions. Attackers can use this marker to influence how Windows handles downloaded content and potentially bypass user warning expectations. The detection relies on Windows stream creation telemetry, including stream contents, the target ADS filename, and the creating process image, while excluding several common browser binaries.
Known false positives
- Other legitimate browsers not currently included in the filter (please add them)
- Legitimate downloads via scripting or command-line tools (Investigate to determine if it's legitimate)
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.