Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)

Alerts when proxy users download common malware and lure file types from hosts using suspicious TLDs.

FreeReviewedSigma · Low · v2
Category
proxy
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-11-07
Updated
2026-07-31

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags proxy web requests where the requested URI ends with high-risk file extensions (e.g., .exe, .vbs, .ps1, Office macros, .hta, .dll, .zip) and the host ends with a set of suspicious or commonly abused top-level domains. Such downloads are a common early step in attacker delivery chains, aiming to get malware or malicious documents onto a victim system. It relies on proxy telemetry that includes the requested URI and destination host, matching by file extension and host TLD suffix.

Related detections9 linkedT1203 — drag to rearrange
Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains
Malicious Script Execution from WinRAR Extraction Directory via CVE-2023-38831
Windows Registry Modification Indicative of CVE-2021-31979 and CVE-2021-33771 Exploitation
Windows file event detection for CVE-2021-31979 and CVE-2021-33771 exploitation artifact paths
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Suspicious OneNote Spawning Script Interpreter (via process_creation)
Suspicious vbc.exe Spawned by Installer Process
Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Pivot detection · T1203 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.