This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Unusual File Download from Direct IP Address
Original Source:
[Sigma source]
Title:
Unusual File Download from Direct IP Address
Status:
test
Description:
Detects the download of suspicious file type from URLs with IP
References:
-https://github.com/trustedsec/SysmonCommunityGuide/blob/adcdfee20999f422b974c8d4149bf4c361237db7/chapters/file-stream-creation-hash.md
-https://labs.withsecure.com/publications/detecting-onenote-abuse
Author:
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)
Date:
2022-09-07
modified:
2023-02-10
Tags:
-'attack.stealth'
-'attack.t1564.004'
Logsource:
product: windows
category: create_stream_hash
Detection:
selection:
Contents|re
:
'http[s]?://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
TargetFilename|contains
:
-'.ps1:Zone'
-'.bat:Zone'
-'.exe:Zone'
-'.vbe:Zone'
-'.vbs:Zone'
-'.dll:Zone'
-'.one:Zone'
-'.cmd:Zone'
-'.hta:Zone'
-'.xll:Zone'
-'.lnk:Zone'
condition
:
selection
Falsepositives:
-Unknown
Level:
high