Linux Process Creation: wget Download Tar From Untrusted Direct IP with No-Check-Certificate

Flags wget commands that download .tar files from direct IP URLs while bypassing TLS certificate validation.

FreeReviewedSigma · High · v5
Product
linux
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-06-16
Updated
2026-07-31
title: "Linux Process Creation: wget Download Tar From Untrusted Direct IP with No-Check-Certificate"
id: 6556af30-3bce-409e-9b05-132aa18d4d0b
status: test
description: This rule flags Linux command execution where wget downloads a .tar file directly from a specified IP address over HTTPS without certificate validation (--no-check-certificate). Such behavior enables attackers to fetch and stage payload archives even when certificate trust is intentionally bypassed. The detection relies on process creation telemetry capturing the executable path/name and the full command line, including the target URL pattern and wget options.
references:
  - https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/UNC4841-Barracuda-ESG-Zero-Day-Exploitation/proc_creation_lnx_apt_unc4841_wget_download_tar_files_direct_ip.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-16
tags:
  - attack.stealth
  - attack.t1140
  - detection.emerging-threats
logsource:
  product: linux
  category: process_creation
detection:
  selection:
    Image|endswith: /wget
    CommandLine|re: https://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}
    CommandLine|contains: --no-check-certificate
    CommandLine|endswith: .tar
  filter_main_local_ips:
    CommandLine|contains:
      - https://10.
      - https://192.168.
      - https://172.16.
      - https://172.17.
      - https://172.18.
      - https://172.19.
      - https://172.20.
      - https://172.21.
      - https://172.22.
      - https://172.23.
      - https://172.24.
      - https://172.25.
      - https://172.26.
      - https://172.27.
      - https://172.28.
      - https://172.29.
      - https://172.30.
      - https://172.31.
      - https://127.
      - https://169.254.
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 23835beb-ec38-4e74-a5d4-b99af6684e91
    type: derived