Suspicious Malware User-Agent Strings in Proxy Logs

Alerts on proxy traffic with user-agent values and substrings commonly seen in malware communications.

FreeUnreviewedSigmahighv1
title: Suspicious Malware User-Agent Strings in Proxy Logs
id: 2a4e639c-dc2c-43d4-b571-cd56908775d8
status: test
description: This rule flags proxy HTTP requests with user-agent strings that match a curated set of suspicious and malware-associated patterns (including exact values and wildcard substrings). Attackers frequently disguise command-and-control traffic and data theft tooling as legitimate clients, so abnormal or reuseable user-agent strings can provide an early signal. The detection relies on proxy log fields containing the client user-agent (c-useragent) and matches against the defined list of suspicious strings.
references:
  - http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-user_agents.rules
  - http://www.botopedia.org/search?searchword=scan&searchphrase=all
  - https://networkraptor.blogspot.com/2015/01/user-agent-strings.html
  - https://perishablepress.com/blacklist/ua-2013.txt
  - https://www.bluecoat.com/en-gb/security-blog/2015-05-05/know-your-agents
  - https://twitter.com/kladblokje_88/status/1614673320124743681?s=12&t=joEpeVa5d58aHYNGA_To7Q
  - https://pbs.twimg.com/media/FtYbfsDXoAQ1Y8M?format=jpg&name=large
  - https://twitter.com/crep1x/status/1635034100213112833
  - https://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_ua_malware.yml
author: Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2017-07-08
modified: 2024-04-14
tags:
  - attack.command-and-control
  - attack.t1071.001
logsource:
  category: proxy
detection:
  selection:
    c-useragent:
      - Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Chrome /53.0
      - Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1)
      - Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0)
      - Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR  1.1.4322)
      - HttpBrowser/1.0
      - "*<|>*"
      - nsis_inetc (mozilla)
      - Wget/1.9+cvs-stable (Red Hat modified)
      - Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; .NET CLR 1.1.4322)
      - "*zeroup*"
      - Mozilla/5.0 (Windows NT 5.1 ; v.*
      - "* adlib/*"
      - "* tiny"
      - "* BGroom *"
      - "* changhuatong"
      - "* CholTBAgent"
      - Mozilla/5.0 WinInet
      - RookIE/1.0
      - M
      - Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
      - Mozilla/4.0 (compatible;MSIE 7.0;Windows NT 6.0)
      - backdoorbot
      - Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30731)
      - Opera/8.81 (Windows NT 6.0; U; en)
      - Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30729)
      - Opera
      - Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
      - Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
      - MSIE
      - "*(Charon; Inferno)"
      - Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/5.0)
      - Mozilla/4.0 (compatible; MSIE 6.1; Windows NT)
      - Mozilla/4.0(compatible; MSIE 6.0; Windows NT 5.1)
      - Mozilla/5.0 (Windows NT 10.0; Win64; x64)
      - Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)
      - Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64)
      - Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; InfoPath.3)
      - Mozilla/5.0 (Windows NT 6.1)
      - AppleWebkit/587.38 (KHTML, like Gecko)
      - Chrome/91.0.4472.77
      - Safari/537.36
      - Edge/91.0.864.37
      - Firefox/89.0
      - Gecko/20100101
      - "* pxyscand*"
      - "* asd"
      - "* mdms"
      - sample
      - nocase
      - Moxilla
      - Win32 *
      - "*Microsoft Internet Explorer*"
      - agent *
      - AutoIt
      - IczelionDownLoad
      - Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 10.0; .NET4.0C; .NET4.0E; Tablet PC 2.0)
      - record
      - mozzzzzzzzzzz
      - Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0
      - Havana/0.1
      - antSword/v2.1
      - rqwrwqrqwrqw
      - qwrqrwrqwrqwr
      - rc2.0/client
      - TakeMyPainBack
      - xxx
      - "20112211"
      - "23591"
      - "901785252112"
      - "1235125521512"
      - "125122112551"
      - B1D3N_RIM_MY_ASS
      - AYAYAYAY1337
      - iMightJustPayMySelfForAFeature
      - ForAFeature
      - Ares_ldr_v_*
      - Microsoft Internet Explorer
      - CLCTR
      - uploader
      - agent
      - License
      - vb wininet
      - Client
      - Lilith-Bot/3.0
      - svc/1.0
      - WSHRAT
      - ZeroStresser Botnet/1.5
      - OK
      - Project1sqlite
      - Project1
      - DuckTales
      - Zadanie
      - GunnaWunnaBlueTips
      - Xlmst
      - GeekingToTheMoon
      - SunShineMoonLight
      - BunnyRequester
      - BunnyTasks
      - BunnyStealer
      - BunnyLoader_Dropper
      - BunnyLoader
      - BunnyShell
      - SPARK-COMMIT
      - 4B4DB4B3
      - SouthSide
      - Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1)
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 5c84856b-55a5-45f1-826f-13f37250cf4e
    type: derived

What it detects

This rule flags proxy HTTP requests with user-agent strings that match a curated set of suspicious and malware-associated patterns (including exact values and wildcard substrings). Attackers frequently disguise command-and-control traffic and data theft tooling as legitimate clients, so abnormal or reuseable user-agent strings can provide an early signal. The detection relies on proxy log fields containing the client user-agent (c-useragent) and matches against the defined list of suspicious strings.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.