Suspicious Exfiltration of Environment File via wget POST

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Execution → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Impact

What it detects

This rule detects reading a dotenv secrets file and posting its contents to a remote host using wget post-data, an exfiltration pattern observed after React2Shell RCE. Attackers grab application secrets from the .env file to pivot into connected cloud and database services. The combination of the .env path and an outbound HTTP post argument reflects deliberate credential theft rather than routine tooling.

Related detections9 linkedT1059.004 — drag to rearrange
Suspicious Data Exfiltration via curl Multipart Upload to Gate Endpoint
Malicious Node.js Process Spawning Unix Shell or Network Client
Malicious Encrypted Reverse Shell via Netcat and GPG on Linux
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious Reverse Shell via Dev TCP or Netcat
Suspicious Base64 Decoded Payload Piped to Shell
Suspicious Shell Spawned by ActiveMQ Java Process
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Suspicious Bad Apples Reverse Shell via socat pty
Suspicious Exfiltration of Environment File via wget POST
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.