Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern

Flags proxy requests with Base64-like URI characters plus '/images/' and '.avi' patterns consistent with Ursnif C2.

FreeReviewedSigma · Critical · v5
Category
proxy
Author
Thomas Patzke (SigmaHQ), DRL 1.1
Published
2019-12-19
Updated
2026-07-31

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. Exfiltration

  11. Impact

What it detects

This rule flags proxy requests whose URI appears to include Base64-encoded content and simultaneously matches an expected path and file pattern: the URI contains '.avi' and '/images/'. Such C2-looking web traffic matters because malware commonly disguises or transforms communications in outbound URLs to blend with normal traffic and hinder inspection. The detection relies on proxy telemetry, inspecting the request URI for specific substrings indicative of encoding and the targeted '.avi' plus '/images/' structure.

Related detections9 linkedT1204.002 — drag to rearrange
Suspicious DLL Written to Explorer IconCache Path
Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious OneNote Spawning Script Interpreter (via process_creation)
Suspicious vbc.exe Spawned by Installer Process
Suspicious Reverse Shell via Dev TCP or Netcat
Malicious HarborWatch RAT Command and Control Beacon by User Agent (via proxy)
Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Pivot detection · T1204.002 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.