Windows ADS Creation with Zone.Identifier Markers Outside Browser Downloads

Flags suspicious creation of :Zone.Identifier ADS streams (ZoneTransfer/ZoneId=3) on file types outside typical browsers.

FreeUnreviewedSigmamediumv1
title: Windows ADS Creation with Zone.Identifier Markers Outside Browser Downloads
id: fb04d0be-226c-4193-a884-681be805aaa4
status: test
description: This rule identifies creation of an Alternate Data Stream (ADS) file that uses ZoneTransfer/ZoneId=3 and targets :Zone.Identifier on filenames matching common executable and script/document extensions. Attackers can use this marker to influence how Windows handles downloaded content and potentially bypass user warning expectations. The detection relies on Windows stream creation telemetry, including stream contents, the target ADS filename, and the creating process image, while excluding several common browser binaries.
references:
  - https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/create_stream_hash/create_stream_hash_creation_internet_file.yml
author: frack113, Huntrule Team
date: 2022-10-22
modified: 2023-06-12
tags:
  - attack.stealth
logsource:
  product: windows
  category: create_stream_hash
detection:
  selection:
    Contents|startswith: "[ZoneTransfer]  ZoneId=3"
    TargetFilename|endswith: :Zone.Identifier
    TargetFilename|contains:
      - .exe
      - .scr
      - .bat
      - .cmd
      - .docx
      - .hta
      - .jse
      - .lnk
      - .pptx
      - .ps
      - .reg
      - .sct
      - .vb
      - .wsc
      - .wsf
      - .xlsx
  filter_optional_brave:
    Image|endswith: \brave.exe
  filter_optional_chrome:
    Image:
      - C:\Program Files\Google\Chrome\Application\chrome.exe
      - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  filter_optional_firefox:
    Image:
      - C:\Program Files\Mozilla Firefox\firefox.exe
      - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  filter_optional_ie:
    Image:
      - C:\Program Files (x86)\Internet Explorer\iexplore.exe
      - C:\Program Files\Internet Explorer\iexplore.exe
  filter_optional_maxthon:
    Image|endswith: \maxthon.exe
  filter_optional_edge_1:
    - Image|startswith: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\
    - Image|endswith: \WindowsApps\MicrosoftEdge.exe
    - Image:
        - C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
        - C:\Program Files\Microsoft\Edge\Application\msedge.exe
  filter_optional_edge_2:
    Image|startswith:
      - C:\Program Files (x86)\Microsoft\EdgeCore\
      - C:\Program Files\Microsoft\EdgeCore\
    Image|endswith:
      - \msedge.exe
      - \msedgewebview2.exe
  filter_optional_opera:
    Image|endswith: \opera.exe
  filter_optional_safari:
    Image|endswith: \safari.exe
  filter_optional_seamonkey:
    Image|endswith: \seamonkey.exe
  filter_optional_vivaldi:
    Image|endswith: \vivaldi.exe
  filter_optional_whale:
    Image|endswith: \whale.exe
  filter_optional_snipping_tool:
    Image|startswith: C:\Program Files\WindowsApps\Microsoft.ScreenSketch_
    Image|endswith: \SnippingTool\SnippingTool.exe
    TargetFilename|startswith: C:\Users\
    TargetFilename|contains|all:
      - \AppData\Local\Packages\Microsoft.ScreenSketch_
      - "\\TempState\\Screenshot "
    TargetFilename|endswith: .png:Zone.Identifier
  condition: selection and not 1 of filter_optional_*
falsepositives:
  - Other legitimate browsers not currently included in the filter (please add them)
  - Legitimate downloads via scripting or command-line tools (Investigate to determine if it's legitimate)
level: medium
license: DRL-1.1
related:
  - id: 573df571-a223-43bc-846e-3f98da481eca
    type: derived

What it detects

This rule identifies creation of an Alternate Data Stream (ADS) file that uses ZoneTransfer/ZoneId=3 and targets :Zone.Identifier on filenames matching common executable and script/document extensions. Attackers can use this marker to influence how Windows handles downloaded content and potentially bypass user warning expectations. The detection relies on Windows stream creation telemetry, including stream contents, the target ADS filename, and the creating process image, while excluding several common browser binaries.

Known false positives

  • Other legitimate browsers not currently included in the filter (please add them)
  • Legitimate downloads via scripting or command-line tools (Investigate to determine if it's legitimate)

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.