Linux Process Creation: wget Download Tar From Untrusted Direct IP with No-Check-Certificate
Flags wget commands that download .tar files from direct IP URLs while bypassing TLS certificate validation.
- Product
- linux
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-06-16
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Linux command execution where wget downloads a .tar file directly from a specified IP address over HTTPS without certificate validation (--no-check-certificate). Such behavior enables attackers to fetch and stage payload archives even when certificate trust is intentionally bypassed. The detection relies on process creation telemetry capturing the executable path/name and the full command line, including the target URL pattern and wget options.
Reporting behind it
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Linux Process Creation: wget Download Tar From Untrusted Direct IP with No-Check-Certificate"
id: 6556af30-3bce-409e-9b05-132aa18d4d0b
status: test
description: This rule flags Linux command execution where wget downloads a .tar file directly from a specified IP address over HTTPS without certificate validation (--no-check-certificate). Such behavior enables attackers to fetch and stage payload archives even when certificate trust is intentionally bypassed. The detection relies on process creation telemetry capturing the executable path/name and the full command line, including the target URL pattern and wget options.
references:
- https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/TA/UNC4841-Barracuda-ESG-Zero-Day-Exploitation/proc_creation_lnx_apt_unc4841_wget_download_tar_files_direct_ip.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-06-16
tags:
- attack.stealth
- attack.t1140
- detection.emerging-threats
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith: /wget
CommandLine|re: https://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}
CommandLine|contains: --no-check-certificate
CommandLine|endswith: .tar
filter_main_local_ips:
CommandLine|contains:
- https://10.
- https://192.168.
- https://172.16.
- https://172.17.
- https://172.18.
- https://172.19.
- https://172.20.
- https://172.21.
- https://172.22.
- https://172.23.
- https://172.24.
- https://172.25.
- https://172.26.
- https://172.27.
- https://172.28.
- https://172.29.
- https://172.30.
- https://172.31.
- https://127.
- https://169.254.
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 23835beb-ec38-4e74-a5d4-b99af6684e91
type: derived