Download From Suspicious TLD - Whitelist

 Original Source: [Sigma source]
Title: Download From Suspicious TLD - Whitelist
Status: test
Description:Detects executable downloads from suspicious remote systems
References:
  -Internal Research
Author: Florian Roth (Nextron Systems)
Date: 2017-03-13
modified:2023-05-18
Tags:
  • -'attack.initial-access'
  • -'attack.t1566'
  • -'attack.execution'
  • -'attack.t1203'
  • -'attack.t1204.002'
Logsource:
  • category: proxy
Detection:
  selection:
    c-uri-extension:
      -'exe'
      -'vbs'
      -'bat'
      -'rar'
      -'ps1'
      -'doc'
      -'docm'
      -'xls'
      -'xlsm'
      -'pptm'
      -'rtf'
      -'hta'
      -'dll'
      -'ws'
      -'wsf'
      -'sct'
      -'zip'

  filter:
    cs-host|endswith:
      -'.com'
      -'.org'
      -'.net'
      -'.edu'
      -'.gov'
      -'.uk'
      -'.ca'
      -'.de'
      -'.jp'
      -'.fr'
      -'.au'
      -'.us'
      -'.ch'
      -'.it'
      -'.nl'
      -'.se'
      -'.no'
      -'.es'

  condition:selection and not filter
Falsepositives:
  -All kind of software downloads
Level: low