PUA Tool Update Check to /checkupdate.php (Advanced IP/Port Scanner) via Proxy

Identifies proxy HTTP requests to /checkupdate.php from Advanced IP/Port Scanner with expected update-check query parameters.

FreeReviewedSigma · Medium · v2
Category
proxy
Author
Axel Olsson (SigmaHQ), DRL 1.1
Published
2022-08-14
Updated
2026-07-31

ATT&CK techniques

Recon
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies HTTP proxy requests whose URI contains /checkupdate.php and includes a query string with lng, ver, beta, type, rmode, and product parameters, consistent with an Advanced IP/Port Scanner update check. Such update-check traffic can be used to support reconnaissance tooling by keeping the utility current while it performs scanning. Detection relies on proxy logs capturing the full request URI and query parameters.

Related detections3 linkedT1590 — drag to rearrange
Suspicious DNS Zone Export via dnscmd for Reconnaissance
Suspicious External IP Discovery via Curl to Ipinfo
Windows DNS Queries for IP Lookup Service Domains from Non-Browser Processes
PUA Tool Update Check to /checkupdate.php (Advanced IP/Port Scanner) via Proxy
Pivot detection · T1590 · 3 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.