Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows

Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.

FreeUnreviewedSigmahighv1
title: Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
id: 90686823-a750-4df0-8c89-2a9c816b49c8
related:
  - id: 8b48ad89-10d8-4382-a546-50588c410f0d
    type: similar
  - id: d635249d-86b5-4dad-a8c7-d7272b788586
    type: similar
  - id: 52182dfb-afb7-41db-b4bc-5336cb29b464
    type: similar
  - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
    type: similar
  - id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
    type: similar
  - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
    type: similar
  - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
    type: similar
  - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
    type: similar
  - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
    type: similar
  - id: a0d7e4d2-bede-4141-8896-bc6e237e977c
    type: similar
  - id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
    type: similar
  - id: b6e04788-29e1-4557-bb14-77f761848ab8
    type: derived
status: test
description: This rule flags Windows PowerShell execution where the command line references common file-sharing and paste-style hosting domains and performs file retrieval using PowerShell download functions or common download/curl-like aliases. Attackers frequently use these mechanisms to pull payloads or additional tooling from externally hosted locations while blending into legitimate scripting activity. It relies on process creation telemetry, specifically the spawned PowerShell image path and the PowerShell command line containing both a file-sharing domain and download-related constructs.
references:
  - https://labs.withsecure.com/publications/fin7-target-veeam-servers
  - https://github.com/WithSecureLabs/iocs/blob/344203de742bb7e68bd56618f66d34be95a9f9fc/FIN7VEEAM/iocs.csv
  - https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
  - https://www.huntress.com/blog/slashandgrab-screen-connect-post-exploitation-in-the-wild-cve-2024-1709-cve-2024-1708
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_download_susp_file_sharing_domains.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2024-02-23
modified: 2026-03-29
tags:
  - attack.execution
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - Image|endswith:
        - \powershell.exe
        - \pwsh.exe
    - OriginalFileName:
        - PowerShell.EXE
        - pwsh.dll
  selection_websites:
    CommandLine|contains:
      - 0x0.st
      - anonfiles.com
      - bashupload.com
      - cdn.discordapp.com
      - chunk.io
      - ddns.net
      - dl.dropboxusercontent.com
      - ghostbin.co
      - glitch.me
      - gofile.io
      - hastebin.com
      - mediafire.com
      - mega.nz
      - onrender.com
      - pages.dev
      - paste.ee
      - pastebin.com
      - pastebin.pl
      - pastetext.net
      - pixeldrain.com
      - privatlab.com
      - privatlab.net
      - send.exploit.in
      - sendspace.com
      - storage.googleapis.com
      - storjshare.io
      - supabase.co
      - temp.sh
      - transfer.sh
      - trycloudflare.com
      - ufile.io
      - w3spaces.com
      - workers.dev
      - x0.at
  selection_download:
    CommandLine|contains:
      - .DownloadString(
      - .DownloadFile(
      - "Invoke-WebRequest "
      - "iwr "
      - "wget "
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags Windows PowerShell execution where the command line references common file-sharing and paste-style hosting domains and performs file retrieval using PowerShell download functions or common download/curl-like aliases. Attackers frequently use these mechanisms to pull payloads or additional tooling from externally hosted locations while blending into legitimate scripting activity. It relies on process creation telemetry, specifically the spawned PowerShell image path and the PowerShell command line containing both a file-sharing domain and download-related constructs.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.