Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains

Finds proxy traffic requesting executable or script/doc payloads from hosts with suspicious TLDs not in the whitelist.

FreeReviewedSigma · Low · v2
Category
proxy
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-03-13
Updated
2026-07-31

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags proxy requests where the requested URI ends with high-risk file extensions (e.g., exe, vbs, bat, ps1, hta, dll) while the host ends with a restricted set of top-level domains. Attackers commonly use web-facing infrastructure to deliver malware or scripts for initial access and execution. The detection relies on proxy telemetry capturing requested URI paths and the destination host.

Related detections9 linkedT1203 — drag to rearrange
Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
Windows Registry Modification Indicative of CVE-2021-31979 and CVE-2021-33771 Exploitation
Windows file event detection for CVE-2021-31979 and CVE-2021-33771 exploitation artifact paths
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious NFe-Themed Brazilian Lure Executable Execution
Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains
Pivot detection · T1203 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.