Unusual File Download from Direct IP Address

 Original Source: [Sigma source]
Title: Unusual File Download from Direct IP Address
Status: test
Description:Detects the download of suspicious file type from URLs with IP
References:
  -https://github.com/trustedsec/SysmonCommunityGuide/blob/adcdfee20999f422b974c8d4149bf4c361237db7/chapters/file-stream-creation-hash.md
  -https://labs.withsecure.com/publications/detecting-onenote-abuse
Author: Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)
Date: 2022-09-07
modified:2023-02-10
Tags:
  • -'attack.stealth'
  • -'attack.t1564.004'
Logsource:
  • product: windows
  • category: create_stream_hash
Detection:
  selection:
    Contents|re: 'http[s]?://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
    TargetFilename|contains:
      -'.ps1:Zone'
      -'.bat:Zone'
      -'.exe:Zone'
      -'.vbe:Zone'
      -'.vbs:Zone'
      -'.dll:Zone'
      -'.one:Zone'
      -'.cmd:Zone'
      -'.hta:Zone'
      -'.xll:Zone'
      -'.lnk:Zone'

  condition:selection
Falsepositives:
  -Unknown
Level: high