Windows Process Creation: CrushFTP Spawns PowerShell/CMD and LOLBins Indicative of CVE-2025-54309 RCE
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
FreeUnreviewedSigmahighv1
windows-process-creation-crushftp-spawns-powershell-cmd-and-lolbins-indicative-o-0fdc7c7f
title: "Windows Process Creation: CrushFTP Spawns PowerShell/CMD and LOLBins Indicative of CVE-2025-54309 RCE"
id: cbcc4858-562d-4600-8e78-491deb0a69e2
status: experimental
description: This rule flags Windows process creation where the parent process is CrushFTP (crushftp.exe) and it spawns PowerShell, CMD, or common living-off-the-land utilities. Such behavior can indicate post-compromise execution consistent with exploiting a remote code execution path and running commands in a stealthy manner (for example, encoded PowerShell with execution policy bypass). The detection relies on process creation telemetry, matching executable paths and command-line substrings for PowerShell/CMD and several auxiliary binaries.
references:
- https://reliaquest.com/blog/threat-spotlight-cve-2025-54309-crushftp-exploit/
- https://pwn.guide/free/web/crushftp
- https://firecompass.com/crushftp-vulnerability-cve-2025-54309-securing-file-transfer-services/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-54309/proc_creation_win_exploit_cve_2025_54309.yml
author: Nisarg Suthar, Huntrule Team
date: 2025-08-01
tags:
- attack.privilege-escalation
- attack.initial-access
- attack.execution
- attack.t1059.001
- attack.t1059.003
- attack.t1068
- attack.t1190
- cve.2025-54309
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: \crushftp.exe
selection_child_powershell:
Image|endswith:
- \powershell.exe
- \powershell_ise.exe
- \pwsh.exe
CommandLine|contains|all:
- IEX
- enc
- Hidden
- bypass
selection_child_cmd:
Image|endswith: \cmd.exe
CommandLine|contains:
- /c powershell
- whoami
- net.exe
- net1.exe
selection_child_others:
Image|endswith:
- \bitsadmin.exe
- \certutil.exe
- \mshta.exe
- \cscript.exe
- \wscript.exe
condition: selection_parent and 1 of selection_child_*
falsepositives:
- Legitimate administrative command execution
level: high
license: DRL-1.1
related:
- id: 0fdc7c7f-c690-4217-9ae3-31f5156eed72
type: derived
What it detects
This rule flags Windows process creation where the parent process is CrushFTP (crushftp.exe) and it spawns PowerShell, CMD, or common living-off-the-land utilities. Such behavior can indicate post-compromise execution consistent with exploiting a remote code execution path and running commands in a stealthy manner (for example, encoded PowerShell with execution policy bypass). The detection relies on process creation telemetry, matching executable paths and command-line substrings for PowerShell/CMD and several auxiliary binaries.
Known false positives
- Legitimate administrative command execution
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.