Skip to content
Threat Feed
low advisory

Detection of Hex-Encoded Payload Execution on Linux

Adversaries utilize hex encoding with common Linux utilities to obfuscate malicious payloads, evading static detection during the execution stage.

Adversaries targeting Linux environments frequently employ hex encoding to obfuscate malicious payloads. By transforming scripts or binary data into hex format, attackers aim to bypass signature-based detection mechanisms and static analysis tools. This technique relies on common system utilities and scripting interpreters to decode or interpret the payload at runtime. The threat is characterized by the use of binaries such as xxd, python, php, ruby, perl, or lua, which contain native functions for hex-to-binary conversion. Defenders must monitor process execution logs for specific command-line arguments that signal the decoding of these payloads. This behavior is often a precursor to further malicious activity, such as the execution of fileless malware or the staging of secondary payloads, necessitating robust monitoring of shell and interpreter invocations.

Attack Chain

  1. Attacker delivers a hex-encoded malicious script or payload to the target Linux system.
  2. Attacker invokes a system utility or scripting interpreter (e.g., Python, PHP) to handle the execution.
  3. The interpreter receives the hex-encoded string as a command-line argument.
  4. The process calls a decoding function (e.g., binascii.unhexlify, hex2bin) to revert the data to its functional binary or script form.
  5. The decoded payload is executed directly in memory or written to a temporary location on the filesystem.
  6. The malicious logic is carried out, potentially leading to persistence, exfiltration, or further system compromise.

Impact

Successful execution of obfuscated payloads allows attackers to bypass security controls, maintain stealth during the initial stages of an attack, and gain unauthorized access or control over Linux endpoints. While the risk score for generic use is low, these techniques are commonly utilized in the early stages of sophisticated intrusions to facilitate malware delivery and command execution without triggering immediate alerts.

Recommendation

Deploy the provided Sigma rule to monitor for suspicious process execution patterns involving hex decoding. Prioritize tuning the rule by identifying and excluding legitimate administrative scripts and development tools that utilize these encoding functions.

  • Enable process creation auditing on all Linux endpoints to capture command-line arguments.
  • Use the Sigma rule to alert on suspicious invocations of xxd, python, php, ruby, perl, and lua.
  • Regularly review exclusion lists to minimize noise from system administration and internal development workflows.

Immediate actions

Deploy Sigma rule to test environment

Detection Engineering 72h

Detection coverage 1

Potential Hex Payload Execution via Common Utility

low

Detects the use of common Linux utilities and interpreters that utilize hex-decoding functions to process command-line arguments, a technique often used to obfuscate malicious payloads.

sigma tactics: defense_evasion, execution techniques: T1027, T1140 sources: process_creation, linux

Detection queries are available on the platform. Get full rules →