{"id":"e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97","title":"Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder","description":"Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2018-08-30","modified":"2026-03-29","tags":["attack.command-and-control","attack.t1105"],"technique_ids":["T1105"],"logsource":{"category":"network_connection","product":"windows"},"falsepositives":["Some installers located in the temp directory might communicate with the Github domains in order to download additional software. Baseline these cases or move the github domain to a lower level hunting rule."],"references":["https://twitter.com/M_haggis/status/900741347035889665","https://twitter.com/M_haggis/status/1032799638213066752","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker","https://www.cisa.gov/uscert/ncas/alerts/aa22-321a","https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/exfil/Invoke-ExfilDataToGitHub.ps1"],"source_path":"rules/windows/network_connection/net_connection_win_susp_file_sharing_domains_susp_folders.yml","source_sha256":"4c022d73d2c3fd9697fcd34eea337e4d9de5cfbaa422eab2e072f2b27f74ef55","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/network_connection/net_connection_win_susp_file_sharing_domains_susp_folders.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder\nid: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97\nrelated:\n    - id: 635dbb88-67b3-4b41-9ea5-a3af2dd88153\n      type: obsolete\n    - id: 8b48ad89-10d8-4382-a546-50588c410f0d\n      type: similar\n    - id: d635249d-86b5-4dad-a8c7-d7272b788586\n      type: similar\n    - id: 52182dfb-afb7-41db-b4bc-5336cb29b464\n      type: similar\n    - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99\n      type: similar\n    - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f\n      type: similar\n    - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c\n      type: similar\n    - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794\n      type: similar\n    - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb\n      type: similar\n    - id: b6e04788-29e1-4557-bb14-77f761848ab8\n      type: similar\n    - id: a0d7e4d2-bede-4141-8896-bc6e237e977c\n      type: similar\n    - id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7\n      type: similar\nstatus: test\ndescription: Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.\nreferences:\n    - https://twitter.com/M_haggis/status/900741347035889665\n    - https://twitter.com/M_haggis/status/1032799638213066752\n    - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker\n    - https://www.cisa.gov/uscert/ncas/alerts/aa22-321a\n    - https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/exfil/Invoke-ExfilDataToGitHub.ps1\nauthor: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)\ndate: 2018-08-30\nmodified: 2026-03-29\ntags:\n    - attack.command-and-control\n    - attack.t1105\nlogsource:\n    category: network_connection\n    product: windows\ndetection:\n    selection_paths:\n        Image|contains:\n            - ':\\$Recycle.bin'\n            - ':\\Perflogs\\'\n            - ':\\Temp\\'\n            - ':\\Users\\Default\\'\n            - ':\\Users\\Public\\'\n            - ':\\Windows\\Fonts\\'\n            - ':\\Windows\\IME\\'\n            - ':\\Windows\\System32\\Tasks\\'\n            - ':\\Windows\\Tasks\\'\n            - ':\\Windows\\Temp\\'\n            - '\\AppData\\Temp\\'\n            - '\\config\\systemprofile\\'\n            - '\\Windows\\addins\\'\n    selection_domains:\n        Initiated: 'true'\n        DestinationHostname|endswith:\n            - '.githubusercontent.com'       # Includes both gists and github repositories / Michael Haag (idea)\n            - '0x0.st'\n            - 'anonfiles.com'\n            - 'bashupload.com'\n            - 'cdn.discordapp.com'\n            - 'chunk.io'\n            - 'ddns.net'\n            - 'dl.dropboxusercontent.com'\n            - 'ghostbin.co'\n            - 'github.com'\n            - 'glitch.me'\n            - 'gofile.io'\n            - 'hastebin.com'\n            - 'mediafire.com'\n            - 'mega.co.nz'\n            - 'mega.nz'\n            - 'onrender.com'\n            - 'pages.dev'\n            - 'paste.ee'\n            - 'pastebin.com'\n            - 'pastebin.pl'\n            - 'pastetext.net'\n            - 'pixeldrain.com'\n            - 'privatlab.com'\n            - 'privatlab.net'\n            - 'send.exploit.in'\n            - 'sendspace.com'\n            - 'storage.googleapis.com'\n            - 'storjshare.io'\n            - 'supabase.co'\n            - 'temp.sh'\n            - 'transfer.sh'\n            - 'trycloudflare.com'\n            - 'ufile.io'\n            - 'w3spaces.com'\n            - 'workers.dev'\n            - 'x0.at'\n    condition: all of selection_*\nfalsepositives:\n    - Some installers located in the temp directory might communicate with the Github domains in order to download additional software. Baseline these cases or move the github domain to a lower level hunting rule.\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1105","id":"T1105","name":"Ingress Tool Transfer","page":"techniques/enterprise/T1105/"}],"data_path":"data/detection-rules/e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97.json","kind":"sigma"}
