BITS Transfer Job With Uncommon Or Suspicious Remote TLD

 Original Source: [Sigma source]
Title: BITS Transfer Job With Uncommon Or Suspicious Remote TLD
Status: test
Description:Detects a suspicious download using the BITS client from a FQDN that is unusual. Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1197/T1197.md
  -https://twitter.com/malmoeb/status/1535142803075960832
Author: Florian Roth (Nextron Systems)
Date: 2022-06-10
modified:2025-02-28
Tags:
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1197'
Logsource:
  • product: windows
  • service: bits-client
Detection:
  selection:
    EventID: '16403'
  filter_main_generic:
    RemoteName|contains:
      -'.azureedge.net/'
      -'.com/'
      -'.sfx.ms/'
      -'download.mozilla.org/'
      -'cdn.onenote.net/'
      -'cdn.office.net/'
      -'tscdn.m365.static.microsoft/'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -This rule doesn't exclude other known TLDs such as ".org" or ".net". It's recommended to apply additional filters for software and scripts that leverage the BITS service
Level: medium