Suspicious Malware User-Agent Strings in Proxy Logs
Alerts on proxy traffic with user-agent values and substrings commonly seen in malware communications.
- Category
- proxy
- Author
- Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2017-07-08
- Updated
- 2026-07-31
ATT&CK techniques
C2Recon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact
What it detects
This rule flags proxy HTTP requests whose user agent matches a hard-coded set of known suspicious or malware-associated strings and patterns. Attackers may use atypical or impersonated user agents to blend in with normal web traffic while reaching command-and-control or delivering payloads. The detection relies on proxy telemetry that includes the client user agent field, matching it against the specified values and wildcards.
Reporting behind it
- rules.emergingthreats.nethttp://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-user_agents.rules
- botopedia.orghttp://www.botopedia.org/search?searchword=scan&searchphrase=all
- networkraptor.blogspot.comhttps://networkraptor.blogspot.com/2015/01/user-agent-strings.html
- perishablepress.comhttps://perishablepress.com/blacklist/ua-2013.txt
- bluecoat.comhttps://www.bluecoat.com/en-gb/security-blog/2015-05-05/know-your-agents
- twitter.comhttps://twitter.com/kladblokje_88/status/1614673320124743681?s=12&t=joEpeVa5d58aHYNGA_To7Q
- pbs.twimg.comhttps://pbs.twimg.com/media/FtYbfsDXoAQ1Y8M?format=jpg&name=large
- twitter.comhttps://twitter.com/crep1x/status/1635034100213112833
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_ua_malware.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Suspicious Malware User-Agent Strings in Proxy Logs
id: 2a4e639c-dc2c-43d4-b571-cd56908775d8
status: test
description: This rule flags proxy HTTP requests whose user agent matches a hard-coded set of known suspicious or malware-associated strings and patterns. Attackers may use atypical or impersonated user agents to blend in with normal web traffic while reaching command-and-control or delivering payloads. The detection relies on proxy telemetry that includes the client user agent field, matching it against the specified values and wildcards.
references:
- http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-user_agents.rules
- http://www.botopedia.org/search?searchword=scan&searchphrase=all
- https://networkraptor.blogspot.com/2015/01/user-agent-strings.html
- https://perishablepress.com/blacklist/ua-2013.txt
- https://www.bluecoat.com/en-gb/security-blog/2015-05-05/know-your-agents
- https://twitter.com/kladblokje_88/status/1614673320124743681?s=12&t=joEpeVa5d58aHYNGA_To7Q
- https://pbs.twimg.com/media/FtYbfsDXoAQ1Y8M?format=jpg&name=large
- https://twitter.com/crep1x/status/1635034100213112833
- https://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_ua_malware.yml
author: Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2017-07-08
modified: 2024-04-14
tags:
- attack.command-and-control
- attack.t1071.001
logsource:
category: proxy
detection:
selection:
c-useragent:
- Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Chrome /53.0
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1)
- Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0)
- Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
- HttpBrowser/1.0
- "*<|>*"
- nsis_inetc (mozilla)
- Wget/1.9+cvs-stable (Red Hat modified)
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; .NET CLR 1.1.4322)
- "*zeroup*"
- Mozilla/5.0 (Windows NT 5.1 ; v.*
- "* adlib/*"
- "* tiny"
- "* BGroom *"
- "* changhuatong"
- "* CholTBAgent"
- Mozilla/5.0 WinInet
- RookIE/1.0
- M
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
- Mozilla/4.0 (compatible;MSIE 7.0;Windows NT 6.0)
- backdoorbot
- Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30731)
- Opera/8.81 (Windows NT 6.0; U; en)
- Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30729)
- Opera
- Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
- Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
- MSIE
- "*(Charon; Inferno)"
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/5.0)
- Mozilla/4.0 (compatible; MSIE 6.1; Windows NT)
- Mozilla/4.0(compatible; MSIE 6.0; Windows NT 5.1)
- Mozilla/5.0 (Windows NT 10.0; Win64; x64)
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)
- Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64)
- Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; InfoPath.3)
- Mozilla/5.0 (Windows NT 6.1)
- AppleWebkit/587.38 (KHTML, like Gecko)
- Chrome/91.0.4472.77
- Safari/537.36
- Edge/91.0.864.37
- Firefox/89.0
- Gecko/20100101
- "* pxyscand*"
- "* asd"
- "* mdms"
- sample
- nocase
- Moxilla
- Win32 *
- "*Microsoft Internet Explorer*"
- agent *
- AutoIt
- IczelionDownLoad
- Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 10.0; .NET4.0C; .NET4.0E; Tablet PC 2.0)
- record
- mozzzzzzzzzzz
- Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0
- Havana/0.1
- antSword/v2.1
- rqwrwqrqwrqw
- qwrqrwrqwrqwr
- rc2.0/client
- TakeMyPainBack
- xxx
- "20112211"
- "23591"
- "901785252112"
- "1235125521512"
- "125122112551"
- B1D3N_RIM_MY_ASS
- AYAYAYAY1337
- iMightJustPayMySelfForAFeature
- ForAFeature
- Ares_ldr_v_*
- Microsoft Internet Explorer
- CLCTR
- uploader
- agent
- License
- vb wininet
- Client
- Lilith-Bot/3.0
- svc/1.0
- WSHRAT
- ZeroStresser Botnet/1.5
- OK
- Project1sqlite
- Project1
- DuckTales
- Zadanie
- GunnaWunnaBlueTips
- Xlmst
- GeekingToTheMoon
- SunShineMoonLight
- BunnyRequester
- BunnyTasks
- BunnyStealer
- BunnyLoader_Dropper
- BunnyLoader
- BunnyShell
- SPARK-COMMIT
- 4B4DB4B3
- SouthSide
- Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1)
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 5c84856b-55a5-45f1-826f-13f37250cf4e
type: derived