Windows Process Creation: CrushFTP Spawns PowerShell/CMD and LOLBins Indicative of CVE-2025-54309 RCE

Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.

FreeUnreviewedSigmahighv1
title: "Windows Process Creation: CrushFTP Spawns PowerShell/CMD and LOLBins Indicative of CVE-2025-54309 RCE"
id: cbcc4858-562d-4600-8e78-491deb0a69e2
status: experimental
description: This rule flags Windows process creation where the parent process is CrushFTP (crushftp.exe) and it spawns PowerShell, CMD, or common living-off-the-land utilities. Such behavior can indicate post-compromise execution consistent with exploiting a remote code execution path and running commands in a stealthy manner (for example, encoded PowerShell with execution policy bypass). The detection relies on process creation telemetry, matching executable paths and command-line substrings for PowerShell/CMD and several auxiliary binaries.
references:
  - https://reliaquest.com/blog/threat-spotlight-cve-2025-54309-crushftp-exploit/
  - https://pwn.guide/free/web/crushftp
  - https://firecompass.com/crushftp-vulnerability-cve-2025-54309-securing-file-transfer-services/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2025/Exploits/CVE-2025-54309/proc_creation_win_exploit_cve_2025_54309.yml
author: Nisarg Suthar, Huntrule Team
date: 2025-08-01
tags:
  - attack.privilege-escalation
  - attack.initial-access
  - attack.execution
  - attack.t1059.001
  - attack.t1059.003
  - attack.t1068
  - attack.t1190
  - cve.2025-54309
  - detection.emerging-threats
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: \crushftp.exe
  selection_child_powershell:
    Image|endswith:
      - \powershell.exe
      - \powershell_ise.exe
      - \pwsh.exe
    CommandLine|contains|all:
      - IEX
      - enc
      - Hidden
      - bypass
  selection_child_cmd:
    Image|endswith: \cmd.exe
    CommandLine|contains:
      - /c powershell
      - whoami
      - net.exe
      - net1.exe
  selection_child_others:
    Image|endswith:
      - \bitsadmin.exe
      - \certutil.exe
      - \mshta.exe
      - \cscript.exe
      - \wscript.exe
  condition: selection_parent and 1 of selection_child_*
falsepositives:
  - Legitimate administrative command execution
level: high
license: DRL-1.1
related:
  - id: 0fdc7c7f-c690-4217-9ae3-31f5156eed72
    type: derived

What it detects

This rule flags Windows process creation where the parent process is CrushFTP (crushftp.exe) and it spawns PowerShell, CMD, or common living-off-the-land utilities. Such behavior can indicate post-compromise execution consistent with exploiting a remote code execution path and running commands in a stealthy manner (for example, encoded PowerShell with execution policy bypass). The detection relies on process creation telemetry, matching executable paths and command-line substrings for PowerShell/CMD and several auxiliary binaries.

Known false positives

  • Legitimate administrative command execution

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.