Windows Suspicious File Stream Downloads From File Sharing Domains With Script Extensions

Alert on Windows file stream hash creation involving downloads from paste/file-sharing domains targeting .bat/.cmd/.ps1 content indicators.

FreeUnreviewedSigmamediumv1
title: Windows Suspicious File Stream Downloads From File Sharing Domains With Script Extensions
id: 99ab6905-8356-4888-b975-722660254ac3
related:
  - id: 8b48ad89-10d8-4382-a546-50588c410f0d
    type: similar
  - id: d635249d-86b5-4dad-a8c7-d7272b788586
    type: similar
  - id: 52182dfb-afb7-41db-b4bc-5336cb29b464
    type: similar
  - id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
    type: similar
  - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
    type: similar
  - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
    type: similar
  - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
    type: similar
  - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
    type: similar
  - id: b6e04788-29e1-4557-bb14-77f761848ab8
    type: similar
  - id: a0d7e4d2-bede-4141-8896-bc6e237e977c
    type: similar
  - id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
    type: similar
  - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
    type: derived
status: test
description: This rule flags Windows events where a file stream download is initiated to a target filename containing script indicators in the format ".bat:Zone", ".cmd:Zone", or ".ps1:Zone". It further restricts matches to destinations whose content includes known public file sharing and paste hosting domains. This behavior matters because attackers commonly use public hosting sites to deliver or stage malicious scripts, and the rule relies on telemetry that records the stream hash creation along with destination content and target filename.
references:
  - https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90015
  - https://www.cisa.gov/uscert/ncas/alerts/aa22-321a
  - https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/create_stream_hash/create_stream_hash_file_sharing_domains_download_unusual_extension.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-08-24
modified: 2026-03-29
tags:
  - attack.stealth
  - attack.s0139
  - attack.t1564.004
logsource:
  product: windows
  category: create_stream_hash
detection:
  selection_domain:
    Contents|contains:
      - .githubusercontent.com
      - 0x0.st
      - anonfiles.com
      - bashupload.com
      - cdn.discordapp.com
      - chunk.io
      - ddns.net
      - dl.dropboxusercontent.com
      - ghostbin.co
      - github.com
      - glitch.me
      - gofile.io
      - hastebin.com
      - mediafire.com
      - mega.nz
      - onrender.com
      - pages.dev
      - paste.ee
      - pastebin.com
      - pastebin.pl
      - pastetext.net
      - pixeldrain.com
      - privatlab.com
      - privatlab.net
      - send.exploit.in
      - sendspace.com
      - storage.googleapis.com
      - storjshare.io
      - supabase.co
      - temp.sh
      - transfer.sh
      - trycloudflare.com
      - ufile.io
      - w3spaces.com
      - workers.dev
      - x0.at
  selection_extension:
    TargetFilename|contains:
      - .bat:Zone
      - .cmd:Zone
      - .ps1:Zone
  condition: all of selection_*
falsepositives:
  - Unknown
level: medium
license: DRL-1.1

What it detects

This rule flags Windows events where a file stream download is initiated to a target filename containing script indicators in the format ".bat:Zone", ".cmd:Zone", or ".ps1:Zone". It further restricts matches to destinations whose content includes known public file sharing and paste hosting domains. This behavior matters because attackers commonly use public hosting sites to deliver or stage malicious scripts, and the rule relies on telemetry that records the stream hash creation along with destination content and target filename.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.