Suspicious Filename with Embedded Base64 Commands

Rule Info

Name
Suspicious Filename with Embedded Base64 Commands
Author
@kostastsale
Description
Detects files with specially crafted filenames that embed Base64-encoded bash payloads designed to execute when processed by shell scripts. These filenames exploit shell interpretation quirks to trigger hidden commands, a technique observed in VShell malware campaigns.
Date
2025-11-22 00:00:00
Modified
None
Id
179b3686-6271-4d87-807d-17d843a8af73
Tags
attack.execution attack.t1059.004 attack.defense-evasion attack.t1027
Type
Community Rule

Rule History

Author
Title
Date
Commit
Kostas
Merge PR #5627 from @tsale - Filename with Embedded Base64 Commands
2025-11-24