Suspicious Malformed User-Agent Strings in Proxy Logs
Flags proxy requests whose User-Agent headers are malformed or match suspicious automation/tooling patterns, excluding known Adobe/Acrobat traffic.
- Category
- proxy
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2017-07-08
- Updated
- 2026-07-31
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags proxy requests with malformed or suspicious User-Agent header values, including misspelled or incorrectly formatted browser identifiers and known suspicious substrings. Attackers may use abnormal User-Agent strings to blend in, evade simple filtering, or tag automated tooling for command-and-control behavior. It relies on proxy telemetry containing the client User-Agent field (c-useragent) to match specific malformed patterns while excluding specified Adobe/Acrobat-related false positives.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Suspicious Malformed User-Agent Strings in Proxy Logs
id: 5e31a491-6a12-4f9f-98b4-6d410ba321aa
status: test
description: This rule flags proxy requests with malformed or suspicious User-Agent header values, including misspelled or incorrectly formatted browser identifiers and known suspicious substrings. Attackers may use abnormal User-Agent strings to blend in, evade simple filtering, or tag automated tooling for command-and-control behavior. It relies on proxy telemetry containing the client User-Agent field (c-useragent) to match specific malformed patterns while excluding specified Adobe/Acrobat-related false positives.
references:
- https://github.com/fastly/waf_testbed/blob/8bfc406551f3045e418cbaad7596cff8da331dfc/templates/default/scanners-user-agents.data.erb
- https://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_ua_susp.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2017-07-08
modified: 2022-10-31
tags:
- attack.command-and-control
- attack.t1071.001
logsource:
category: proxy
detection:
selection1:
c-useragent|startswith:
- user-agent
- "Mozilla/3.0 "
- "Mozilla/2.0 "
- "Mozilla/1.0 "
- "Mozilla "
- " Mozilla/"
- Mozila/
- Mozilla/4.0 (compatible; MSIE 6.0; MS Web Services Client Protocol
selection2:
c-useragent|contains:
- " (compatible;MSIE "
- ".0;Windows NT "
- loader
selection3:
c-useragent:
- _
- CertUtil URL Agent
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.0)
- Mozilla/5.0 (Windows NT 6.3; WOW64; rv:28.0) Gecko/20100101 Firefox/28.0
- HTTPS
- Erbium-UA-4ce7c27cb4be9d32e333bf032c88235a
- x
- xxx
falsepositives:
- c-useragent: Mozilla/3.0 * Acrobat *
- cs-host|endswith:
- .acrobat.com
- .adobe.com
- .adobe.io
condition: 1 of selection* and not falsepositives
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 7195a772-4b3f-43a4-a210-6a003d65caa1
type: derived