Linux Process Execution: wget Downloading tar via Untrusted IP with Certificate Bypass

Flags wget commands that download .tar files from direct IP URLs while bypassing TLS certificate validation.

FreeUnreviewedSigmahighv1
title: "Linux Process Execution: wget Downloading tar via Untrusted IP with Certificate Bypass"
id: 6556af30-3bce-409e-9b05-132aa18d4d0b
status: test
description: This rule identifies Linux process executions where wget is used to download a .tar file from a URL pointing to a specific IP address and where TLS certificate validation is explicitly disabled. Attackers may use this to fetch and stage payloads when certificate checks would otherwise block the download. The detection relies on process creation telemetry, matching the wget binary name, the presence of a direct IP-based HTTPS URL, and the use of the --no-check-certificate flag.
references:
  - https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/UNC4841-Barracuda-ESG-Zero-Day-Exploitation/proc_creation_lnx_apt_unc4841_wget_download_tar_files_direct_ip.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-16
tags:
  - attack.stealth
  - attack.t1140
  - detection.emerging-threats
logsource:
  product: linux
  category: process_creation
detection:
  selection:
    Image|endswith: /wget
    CommandLine|re: https://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}
    CommandLine|contains: --no-check-certificate
    CommandLine|endswith: .tar
  filter_main_local_ips:
    CommandLine|contains:
      - https://10.
      - https://192.168.
      - https://172.16.
      - https://172.17.
      - https://172.18.
      - https://172.19.
      - https://172.20.
      - https://172.21.
      - https://172.22.
      - https://172.23.
      - https://172.24.
      - https://172.25.
      - https://172.26.
      - https://172.27.
      - https://172.28.
      - https://172.29.
      - https://172.30.
      - https://172.31.
      - https://127.
      - https://169.254.
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 23835beb-ec38-4e74-a5d4-b99af6684e91
    type: derived

What it detects

This rule identifies Linux process executions where wget is used to download a .tar file from a URL pointing to a specific IP address and where TLS certificate validation is explicitly disabled. Attackers may use this to fetch and stage payloads when certificate checks would otherwise block the download. The detection relies on process creation telemetry, matching the wget binary name, the presence of a direct IP-based HTTPS URL, and the use of the --no-check-certificate flag.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.