Suspicious Obfuscated IP Through CLI (via process_creation)
This rule detects use of an encoded/obfuscated version of an IP address (hex, octal, etc.) via command line
SigmamediumWindowsv1
sigma
suspicious-obfuscated-ip-through-cli-via-process-creation
title: Suspicious Obfuscated IP Through CLI (via process_creation)
id: 1b91c100-b32b-5a52-b99f-e7a861550328
status: stable
description: This rule detects use of an encoded/obfuscated version of an IP address (hex, octal, etc.) via command line
references:
- https://h.43z.one/ipconverter/
- https://twitter.com/Yasser_Elsnbary/status/1553804135354564608
author: Huntrule Team
date: 2026-02-08
tags:
- attack.discovery
- attack.defense-evasion
- attack.t1027
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\ping.exe'
- '\arp.exe'
selection_ip_1:
CommandLine|contains:
- ' 0x'
- '//0x'
- '.0x'
- '.00x'
selection_ip_2:
CommandLine|contains|all:
- 'http://%'
- '%2e'
selection_ip_3:
- CommandLine|re: 'https?://[0-9]{1,3}\.[0-9]{1,3}\.0[0-9]{3,4}'
- CommandLine|re: 'https?://[0-9]{1,3}\.0[0-9]{3,7}'
- CommandLine|re: 'https?://0[0-9]{3,11}'
- CommandLine|re: 'https?://(?:0[0-9]{1,11}\.){3}0[0-9]{1,11}'
- CommandLine|re: 'https?://0[0-9]{1,11}'
- CommandLine|re: ' [0-7]{7,13}'
filter_main_valid_ip:
CommandLine|re: 'https?://(?:(?:25[0-5]|(?:2[0-4]|1\d|[1-9])?\d)(?:\.|\b)){4}'
condition: selection_img and 1 of selection_ip_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.