Linux Process Execution: wget Downloading tar via Untrusted IP with Certificate Bypass
Flags wget commands that download .tar files from direct IP URLs while bypassing TLS certificate validation.
FreeUnreviewedSigmahighv1
linux-process-execution-wget-downloading-tar-via-untrusted-ip-with-certificate-b-23835beb
title: "Linux Process Execution: wget Downloading tar via Untrusted IP with Certificate Bypass"
id: 6556af30-3bce-409e-9b05-132aa18d4d0b
status: test
description: This rule identifies Linux process executions where wget is used to download a .tar file from a URL pointing to a specific IP address and where TLS certificate validation is explicitly disabled. Attackers may use this to fetch and stage payloads when certificate checks would otherwise block the download. The detection relies on process creation telemetry, matching the wget binary name, the presence of a direct IP-based HTTPS URL, and the use of the --no-check-certificate flag.
references:
- https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/UNC4841-Barracuda-ESG-Zero-Day-Exploitation/proc_creation_lnx_apt_unc4841_wget_download_tar_files_direct_ip.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-16
tags:
- attack.stealth
- attack.t1140
- detection.emerging-threats
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith: /wget
CommandLine|re: https://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}
CommandLine|contains: --no-check-certificate
CommandLine|endswith: .tar
filter_main_local_ips:
CommandLine|contains:
- https://10.
- https://192.168.
- https://172.16.
- https://172.17.
- https://172.18.
- https://172.19.
- https://172.20.
- https://172.21.
- https://172.22.
- https://172.23.
- https://172.24.
- https://172.25.
- https://172.26.
- https://172.27.
- https://172.28.
- https://172.29.
- https://172.30.
- https://172.31.
- https://127.
- https://169.254.
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 23835beb-ec38-4e74-a5d4-b99af6684e91
type: derived
What it detects
This rule identifies Linux process executions where wget is used to download a .tar file from a URL pointing to a specific IP address and where TLS certificate validation is explicitly disabled. Attackers may use this to fetch and stage payloads when certificate checks would otherwise block the download. The detection relies on process creation telemetry, matching the wget binary name, the presence of a direct IP-based HTTPS URL, and the use of the --no-check-certificate flag.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.