Suspicious Curl.EXE Download

 Original Source: [Sigma source]
Title: Suspicious Curl.EXE Download
Status: test
Description:Detects a suspicious curl process start on Windows and outputs the requested document to a local file
References:
  -https://twitter.com/max_mal_/status/1542461200797163522
  -https://web.archive.org/web/20200128160046/https://twitter.com/reegun21/status/1222093798009790464
  -https://github.com/pr0xylife/Qakbot/blob/4f0795d79dabee5bc9dd69f17a626b48852e7869/Qakbot_AA_23.06.2022.txt
  -https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/
  -https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1105/T1105.md#atomic-test-18---curl-download-file
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2020-07-03
modified:2023-02-21
Tags:
  • -'attack.command-and-control'
  • -'attack.t1105'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_curl:
Image|endswith:'\curl.exe' Product:'The curl executable'   selection_susp_locations:
    CommandLine|contains:
      -'%AppData%'
      -'%Public%'
      -'%Temp%'
      -'%tmp%'
      -'\AppData\'
      -'\Desktop\'
      -'\Temp\'
      -'\Users\Public\'
      -'C:\PerfLogs\'
      -'C:\ProgramData\'
      -'C:\Windows\Temp\'

  selection_susp_extensions:
    CommandLine|endswith:
      -'.dll'
      -'.gif'
      -'.jpeg'
      -'.jpg'
      -'.png'
      -'.temp'
      -'.tmp'
      -'.txt'
      -'.vbe'
      -'.vbs'

  filter_optional_git_windows:
    ParentImage: 'C:\Program Files\Git\usr\bin\sh.exe'
    Image: 'C:\Program Files\Git\mingw64\bin\curl.exe'
    CommandLine|contains|all:
      -'--silent --show-error --output '
      -'gfw-httpget-'
      -'AppData'

  condition:selection_curl and 1 of selection_susp_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: high