Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
FreeUnreviewedSigmahighv1
suspicious-file-downloads-via-powershell-exe-from-file-sharing-domains-on-window-b6e04788
title: Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
id: 90686823-a750-4df0-8c89-2a9c816b49c8
related:
- id: 8b48ad89-10d8-4382-a546-50588c410f0d
type: similar
- id: d635249d-86b5-4dad-a8c7-d7272b788586
type: similar
- id: 52182dfb-afb7-41db-b4bc-5336cb29b464
type: similar
- id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
type: similar
- id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
type: similar
- id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
type: similar
- id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
type: similar
- id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
type: similar
- id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
type: similar
- id: a0d7e4d2-bede-4141-8896-bc6e237e977c
type: similar
- id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
type: similar
- id: b6e04788-29e1-4557-bb14-77f761848ab8
type: derived
status: test
description: This rule flags Windows PowerShell execution where the command line references common file-sharing and paste-style hosting domains and performs file retrieval using PowerShell download functions or common download/curl-like aliases. Attackers frequently use these mechanisms to pull payloads or additional tooling from externally hosted locations while blending into legitimate scripting activity. It relies on process creation telemetry, specifically the spawned PowerShell image path and the PowerShell command line containing both a file-sharing domain and download-related constructs.
references:
- https://labs.withsecure.com/publications/fin7-target-veeam-servers
- https://github.com/WithSecureLabs/iocs/blob/344203de742bb7e68bd56618f66d34be95a9f9fc/FIN7VEEAM/iocs.csv
- https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
- https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_download_susp_file_sharing_domains.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2024-02-23
modified: 2026-03-29
tags:
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith:
- \powershell.exe
- \pwsh.exe
- OriginalFileName:
- PowerShell.EXE
- pwsh.dll
selection_websites:
CommandLine|contains:
- 0x0.st
- anonfiles.com
- bashupload.com
- cdn.discordapp.com
- chunk.io
- ddns.net
- dl.dropboxusercontent.com
- ghostbin.co
- glitch.me
- gofile.io
- hastebin.com
- mediafire.com
- mega.nz
- onrender.com
- pages.dev
- paste.ee
- pastebin.com
- pastebin.pl
- pastetext.net
- pixeldrain.com
- privatlab.com
- privatlab.net
- send.exploit.in
- sendspace.com
- storage.googleapis.com
- storjshare.io
- supabase.co
- temp.sh
- transfer.sh
- trycloudflare.com
- ufile.io
- w3spaces.com
- workers.dev
- x0.at
selection_download:
CommandLine|contains:
- .DownloadString(
- .DownloadFile(
- "Invoke-WebRequest "
- "iwr "
- "wget "
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags Windows PowerShell execution where the command line references common file-sharing and paste-style hosting domains and performs file retrieval using PowerShell download functions or common download/curl-like aliases. Attackers frequently use these mechanisms to pull payloads or additional tooling from externally hosted locations while blending into legitimate scripting activity. It relies on process creation telemetry, specifically the spawned PowerShell image path and the PowerShell command line containing both a file-sharing domain and download-related constructs.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.