Suspicious FRP Proxy Download via wget to Temporary Directory (via process_creation)

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

C2
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. Exfiltration

  13. Impact

What it detects

This rule detects wget fetching the FRP fast reverse proxy binary into a temporary directory after Ivanti EPMM exploitation for tunneling and SOCKS proxying. Attackers staged frpc under hidden /tmp paths to establish covert network access. Downloading frpc to /tmp is a strong lateral movement and C2 indicator.

Related detections9 linkedT1105 — drag to rearrange
Suspicious curl Download Spawned by Excel via IQY Attachment (via process_creation)
Suspicious Remote Payload Staging via curl Piped to Shell (via process_creation)
Suspicious DLL Download to ProgramData via Start-BitsTransfer (via process_creation)
Suspicious PowerShell Script Fetching Remote Batch File From Paste Site (via ps_script)
Suspicious PowerShell Download of Payload From Pastebin (via process_creation)
Suspicious PowerShell Remote Download and Execution via Invoke-WebRequest
Suspicious File Download to Shared Memory Directory on Linux
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious Curl Download From Sysinternals Live Service (via process_creation)
Suspicious FRP Proxy Download via wget to Temporary Directory (via process_creation)
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.