LoFP LoFP / some legitimate apps use this, but limited.

Techniques

Sample rules

Suspicious Download From File-Sharing Website Via Bitsadmin

Description

Detects usage of bitsadmin downloading a file from a suspicious domain

Detection logic

condition: all of selection_*
selection_domain:
  CommandLine|contains:
  - .githubusercontent.com
  - anonfiles.com
  - cdn.discordapp.com
  - cdn.discordapp.com/attachments/
  - ddns.net
  - dl.dropboxusercontent.com
  - ghostbin.co
  - glitch.me
  - gofile.io
  - hastebin.com
  - mediafire.com
  - mega.nz
  - onrender.com
  - paste.ee
  - pastebin.com
  - pastebin.pl
  - pastetext.net
  - privatlab.com
  - privatlab.net
  - send.exploit.in
  - sendspace.com
  - storage.googleapis.com
  - storjshare.io
  - supabase.co
  - temp.sh
  - transfer.sh
  - ufile.io
selection_flags:
  CommandLine|contains:
  - ' /transfer '
  - ' /create '
  - ' /addfile '
selection_img:
- Image|endswith: \bitsadmin.exe
- OriginalFileName: bitsadmin.exe

File Download Via Bitsadmin

Description

Detects usage of bitsadmin downloading a file

Detection logic

condition: selection_img and (selection_cmd or all of selection_cli_*)
selection_cli_1:
  CommandLine|contains:
  - ' /create '
  - ' /addfile '
selection_cli_2:
  CommandLine|contains: http
selection_cmd:
  CommandLine|contains: ' /transfer '
selection_img:
- Image|endswith: \bitsadmin.exe
- OriginalFileName: bitsadmin.exe