Suspicious curl.exe File Downloads From Direct IP Addresses on Windows
Alerts on Windows curl.exe commands downloading from an IP address with HTTP/S and suspect file extensions.
- Product
- windows
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-07-27
- Updated
- 2026-07-31
What it detects
This rule flags Windows process creation events where curl.exe is invoked with a URL pointing directly to an IP address, and the command indicates an HTTP download. It further narrows to cases where curl output targets potentially executable or script-related file types (e.g., .exe, .dll, .ps1, .bat) using common download/output flags such as -O, --remote-name, or --output. Attackers may use curl to fetch payloads or scripts directly from an IP to bypass typical domain-based controls, so matching on process command-line telemetry and file extension indicators is key for detection.
Reporting behind it
- labs.withsecure.comhttps://labs.withsecure.com/publications/fin7-target-veeam-servers
- github.comhttps://github.com/WithSecureLabs/iocs/blob/344203de742bb7e68bd56618f66d34be95a9f9fc/FIN7VEEAM/iocs.csv
- github.comhttps://github.com/pr0xylife/IcedID/blob/8dd1e218460db4f750d955b4c65b2f918a1db906/icedID_09.28.2023.txt
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_curl_download_direct_ip_susp_extensions.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Suspicious curl.exe File Downloads From Direct IP Addresses on Windows
id: c4bd4581-4b38-47ec-b6e2-6e56cc7380c5
status: test
description: This rule flags Windows process creation events where curl.exe is invoked with a URL pointing directly to an IP address, and the command indicates an HTTP download. It further narrows to cases where curl output targets potentially executable or script-related file types (e.g., .exe, .dll, .ps1, .bat) using common download/output flags such as -O, --remote-name, or --output. Attackers may use curl to fetch payloads or scripts directly from an IP to bypass typical domain-based controls, so matching on process command-line telemetry and file extension indicators is key for detection.
references:
- https://labs.withsecure.com/publications/fin7-target-veeam-servers
- https://github.com/WithSecureLabs/iocs/blob/344203de742bb7e68bd56618f66d34be95a9f9fc/FIN7VEEAM/iocs.csv
- https://github.com/pr0xylife/IcedID/blob/8dd1e218460db4f750d955b4c65b2f918a1db906/icedID_09.28.2023.txt
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_curl_download_direct_ip_susp_extensions.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-07-27
tags:
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \curl.exe
- OriginalFileName: curl.exe
selection_ip:
CommandLine|re: ://[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}
selection_http:
CommandLine|contains: http
selection_flag:
CommandLine|contains:
- " -O"
- --remote-name
- --output
selection_ext:
CommandLine|endswith:
- .bat
- .bat"
- .dat
- .dat"
- .dll
- .dll"
- .exe
- .exe"
- .gif
- .gif"
- .hta
- .hta"
- .jpeg
- .jpeg"
- .log
- .log"
- .msi
- .msi"
- .png
- .png"
- .ps1
- .ps1"
- .psm1
- .psm1"
- .vbe
- .vbe"
- .vbs
- .vbs"
- .bat'
- .dat'
- .dll'
- .exe'
- .gif'
- .hta'
- .jpeg'
- .log'
- .msi'
- .png'
- .ps1'
- .psm1'
- .vbe'
- .vbs'
condition: all of selection_*
falsepositives:
- Unknown
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_curl_download_direct_ip_susp_extensions/info.yml
license: DRL-1.1
related:
- id: 5cb299fc-5fb1-4d07-b989-0644c68b6043
type: derived