Detection rules › Sigma

BITS Transfer Job Download From File Sharing Domains

Severity
high
Author
Florian Roth (Nextron Systems)
Source
upstream

Detects BITS transfer job downloading files from a file sharing domain.

MITRE ATT&CK coverage

TacticTechniques
PersistenceT1197 BITS Jobs
Defense EvasionT1197 BITS Jobs

Event coverage

ProviderEvent IDTitle
Bits-Client16403

Stages and Predicates

Stage 1: selection

or:
RemoteName|contains: .githubusercontent.com
RemoteName|contains: anonfiles.com
RemoteName|contains: cdn.discordapp.com
RemoteName|contains: ddns.net
RemoteName|contains: dl.dropboxusercontent.com
RemoteName|contains: ghostbin.co
RemoteName|contains: github.com
RemoteName|contains: glitch.me
RemoteName|contains: gofile.io
RemoteName|contains: hastebin.com
RemoteName|contains: mediafire.com
RemoteName|contains: mega.nz
RemoteName|contains: onrender.com
RemoteName|contains: pages.dev
RemoteName|contains: paste.ee
RemoteName|contains: pastebin.com
RemoteName|contains: pastebin.pl
RemoteName|contains: pastetext.net
RemoteName|contains: pixeldrain.com
RemoteName|contains: privatlab.com
RemoteName|contains: privatlab.net
RemoteName|contains: send.exploit.in
RemoteName|contains: sendspace.com
RemoteName|contains: storage.googleapis.com
RemoteName|contains: storjshare.io
RemoteName|contains: supabase.co
RemoteName|contains: temp.sh
RemoteName|contains: transfer.sh
RemoteName|contains: trycloudflare.com
RemoteName|contains: ufile.io
RemoteName|contains: w3spaces.com
RemoteName|contains: workers.dev

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
RemoteNamematch
  • .githubusercontent.com
  • anonfiles.com
  • cdn.discordapp.com
  • ddns.net
  • dl.dropboxusercontent.com
  • ghostbin.co
  • github.com
  • glitch.me
  • gofile.io
  • hastebin.com
  • mediafire.com
  • mega.nz
  • onrender.com
  • pages.dev
  • paste.ee
  • pastebin.com
  • pastebin.pl
  • pastetext.net
  • pixeldrain.com
  • privatlab.com
  • privatlab.net
  • send.exploit.in
  • sendspace.com
  • storage.googleapis.com
  • storjshare.io
  • supabase.co
  • temp.sh
  • transfer.sh
  • trycloudflare.com
  • ufile.io
  • w3spaces.com
  • workers.dev

Neighbors

Broader alternatives (more inclusive than this rule)

These rules match a superset of what this rule catches. They cover the same events plus more. Use them if you want wider coverage and can absorb more false positives.