Detection rules › Sigma

File Download Via Bitsadmin To A Suspicious Target Folder

Severity
high
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Detects usage of bitsadmin downloading a file to a suspicious target folder

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1197 BITS Jobs
Defense EvasionT1036.003 Masquerading: Rename Legitimate Utilities, T1197 BITS Jobs
Command & ControlT1105 Ingress Tool Transfer

Event coverage

ProviderEvent IDTitle
Sysmon1Process creation

Stages and Predicates

Stage 1: all of selection_img

or:
Image|endswith: '\bitsadmin.exe'
OriginalFileName: bitsadmin.exe

Stage 2: all of selection_flags

or:
CommandLine|contains: ' /addfile '
CommandLine|contains: ' /create '
CommandLine|contains: ' /transfer '

Stage 3: all of selection_folder

or:
CommandLine|contains: '%ProgramData%'
CommandLine|contains: '%public%'
CommandLine|contains: '%temp%'
CommandLine|contains: '%tmp%'
CommandLine|contains: ':\Perflogs'
CommandLine|contains: ':\ProgramData\'
CommandLine|contains: ':\Temp\'
CommandLine|contains: ':\Users\Public\'
CommandLine|contains: ':\Windows\'
CommandLine|contains: '\$Recycle.Bin\'
CommandLine|contains: '\AppData\Local\'
CommandLine|contains: '\AppData\Roaming\'
CommandLine|contains: '\Contacts\'
CommandLine|contains: '\Desktop\'
CommandLine|contains: '\Favorites\'
CommandLine|contains: '\Favourites\'
CommandLine|contains: '\Music\'
CommandLine|contains: '\Pictures\'
CommandLine|contains: '\Start Menu\Programs\Startup\'
CommandLine|contains: '\Users\Default\'
CommandLine|contains: '\Videos\'
CommandLine|contains: '\inetpub\wwwroot\'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
CommandLinematch
  • /addfile corpus 5 (sigma 5)
  • /create corpus 14 (sigma 14)
  • /transfer corpus 5 (sigma 5)
  • %ProgramData% corpus 4 (sigma 4)
  • %public%
  • %temp% corpus 5 (sigma 5)
  • %tmp% corpus 9 (sigma 9)
  • :\Perflogs corpus 3 (sigma 3)
  • :\ProgramData\ corpus 5 (sigma 5)
  • :\Temp\ corpus 14 (sigma 14)
  • :\Users\Public\ corpus 14 (sigma 14)
  • :\Windows\ corpus 2 (sigma 2)
  • \$Recycle.Bin\
  • \AppData\Local\ corpus 8 (sigma 8)
  • \AppData\Roaming\ corpus 10 (sigma 10)
  • \Contacts\ corpus 6 (sigma 6)
  • \Desktop\ corpus 11 (sigma 11)
  • \Favorites\ corpus 6 (sigma 6)
  • \Favourites\ corpus 6 (sigma 6)
  • \Music\ corpus 2 (sigma 2)
  • \Pictures\ corpus 3 (sigma 3)
  • \Start Menu\Programs\Startup\
  • \Users\Default\
  • \Videos\ corpus 2 (sigma 2)
  • \inetpub\wwwroot\
Imageends_with
  • \bitsadmin.exe corpus 23 (sigma 23)
OriginalFileNameeq
  • bitsadmin.exe corpus 9 (sigma 9)