File Download From Browser Process Via Inline URL

 Original Source: [Sigma source]
Title: File Download From Browser Process Via Inline URL
Status: test
Description:Detects execution of a browser process with a URL argument pointing to a file with a potentially interesting extension. This can be abused to download arbitrary files or to hide from the user for example by launching the browser in a minimized state.
References:
  -https://twitter.com/mrd0x/status/1478116126005641220
  -https://lolbas-project.github.io/lolbas/Binaries/Msedge/
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2022-01-11
modified:2025-10-27
Tags:
  • -'attack.command-and-control'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
    Image|endswith:
      -'\brave.exe'
      -'\chrome.exe'
      -'\msedge.exe'
      -'\opera.exe'
      -'\vivaldi.exe'

  selection_http:
    CommandLine|contains: 'http'
  selection_extensions:
    - CommandLine|endswith:
      - '.7z'
      - '.dat'
      - '.dll'
      - '.exe'
      - '.hta'
      - '.ps1'
      - '.psm1'
      - '.txt'
      - '.vbe'
      - '.vbs'
      - '.zip'
    - CommandLine|contains:
      - '.7z"'
      - '.dat"'
      - '.dll"'
      - '.hta"'
      - '.ps1"'
      - '.psm1"'
      - '.txt"'
      - '.vbe"'
      - '.vbs"'
      - '.zip"'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium