Suspicious Malware User-Agent Strings in Proxy Logs
Alerts on proxy traffic with user-agent values and substrings commonly seen in malware communications.
FreeUnreviewedSigmahighv1
suspicious-malware-user-agent-strings-in-proxy-logs-5c84856b
title: Suspicious Malware User-Agent Strings in Proxy Logs
id: 2a4e639c-dc2c-43d4-b571-cd56908775d8
status: test
description: This rule flags proxy HTTP requests with user-agent strings that match a curated set of suspicious and malware-associated patterns (including exact values and wildcard substrings). Attackers frequently disguise command-and-control traffic and data theft tooling as legitimate clients, so abnormal or reuseable user-agent strings can provide an early signal. The detection relies on proxy log fields containing the client user-agent (c-useragent) and matches against the defined list of suspicious strings.
references:
- http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-user_agents.rules
- http://www.botopedia.org/search?searchword=scan&searchphrase=all
- https://networkraptor.blogspot.com/2015/01/user-agent-strings.html
- https://perishablepress.com/blacklist/ua-2013.txt
- https://www.bluecoat.com/en-gb/security-blog/2015-05-05/know-your-agents
- https://twitter.com/kladblokje_88/status/1614673320124743681?s=12&t=joEpeVa5d58aHYNGA_To7Q
- https://pbs.twimg.com/media/FtYbfsDXoAQ1Y8M?format=jpg&name=large
- https://twitter.com/crep1x/status/1635034100213112833
- https://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_ua_malware.yml
author: Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2017-07-08
modified: 2024-04-14
tags:
- attack.command-and-control
- attack.t1071.001
logsource:
category: proxy
detection:
selection:
c-useragent:
- Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Chrome /53.0
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1)
- Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0)
- Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
- HttpBrowser/1.0
- "*<|>*"
- nsis_inetc (mozilla)
- Wget/1.9+cvs-stable (Red Hat modified)
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; .NET CLR 1.1.4322)
- "*zeroup*"
- Mozilla/5.0 (Windows NT 5.1 ; v.*
- "* adlib/*"
- "* tiny"
- "* BGroom *"
- "* changhuatong"
- "* CholTBAgent"
- Mozilla/5.0 WinInet
- RookIE/1.0
- M
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
- Mozilla/4.0 (compatible;MSIE 7.0;Windows NT 6.0)
- backdoorbot
- Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30731)
- Opera/8.81 (Windows NT 6.0; U; en)
- Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30729)
- Opera
- Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
- MSIE
- "*(Charon; Inferno)"
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/5.0)
- Mozilla/4.0 (compatible; MSIE 6.1; Windows NT)
- Mozilla/4.0(compatible; MSIE 6.0; Windows NT 5.1)
- Mozilla/5.0 (Windows NT 10.0; Win64; x64)
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64)
- Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; InfoPath.3)
- Mozilla/5.0 (Windows NT 6.1)
- AppleWebkit/587.38 (KHTML, like Gecko)
- Chrome/91.0.4472.77
- Safari/537.36
- Edge/91.0.864.37
- Firefox/89.0
- Gecko/20100101
- "* pxyscand*"
- "* asd"
- "* mdms"
- sample
- nocase
- Moxilla
- Win32 *
- "*Microsoft Internet Explorer*"
- agent *
- AutoIt
- IczelionDownLoad
- Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 10.0; .NET4.0C; .NET4.0E; Tablet PC 2.0)
- record
- mozzzzzzzzzzz
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0
- Havana/0.1
- antSword/v2.1
- rqwrwqrqwrqw
- qwrqrwrqwrqwr
- rc2.0/client
- TakeMyPainBack
- xxx
- "20112211"
- "23591"
- "901785252112"
- "1235125521512"
- "125122112551"
- B1D3N_RIM_MY_ASS
- AYAYAYAY1337
- iMightJustPayMySelfForAFeature
- ForAFeature
- Ares_ldr_v_*
- Microsoft Internet Explorer
- CLCTR
- uploader
- agent
- License
- vb wininet
- Client
- Lilith-Bot/3.0
- svc/1.0
- WSHRAT
- ZeroStresser Botnet/1.5
- OK
- Project1sqlite
- Project1
- DuckTales
- Zadanie
- GunnaWunnaBlueTips
- Xlmst
- GeekingToTheMoon
- SunShineMoonLight
- BunnyRequester
- BunnyTasks
- BunnyStealer
- BunnyLoader_Dropper
- BunnyLoader
- BunnyShell
- SPARK-COMMIT
- 4B4DB4B3
- SouthSide
- Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1)
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 5c84856b-55a5-45f1-826f-13f37250cf4e
type: derived
What it detects
This rule flags proxy HTTP requests with user-agent strings that match a curated set of suspicious and malware-associated patterns (including exact values and wildcard substrings). Attackers frequently disguise command-and-control traffic and data theft tooling as legitimate clients, so abnormal or reuseable user-agent strings can provide an early signal. The detection relies on proxy log fields containing the client user-agent (c-useragent) and matches against the defined list of suspicious strings.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.