Windows BITS Client Download From File-Sharing Domains
Alerts on Windows BITS transfers (EventID 16403) that download from known file-sharing/content hosting domains.
FreeUnreviewedSigmahighv1
windows-bits-client-download-from-file-sharing-domains-d635249d
title: Windows BITS Client Download From File-Sharing Domains
id: 4f091046-0675-4655-860c-2410db4a1d20
related:
- id: 8b48ad89-10d8-4382-a546-50588c410f0d
type: similar
- id: 52182dfb-afb7-41db-b4bc-5336cb29b464
type: similar
- id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
type: similar
- id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
type: similar
- id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
type: similar
- id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
type: similar
- id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
type: similar
- id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
type: similar
- id: b6e04788-29e1-4557-bb14-77f761848ab8
type: similar
- id: a0d7e4d2-bede-4141-8896-bc6e237e977c
type: similar
- id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
type: similar
- id: d635249d-86b5-4dad-a8c7-d7272b788586
type: derived
status: test
description: This rule flags Windows BITS client activity where a BITS transfer downloads from specific file-sharing and content hosting domains. Such downloads can be used by attackers to stealthily retrieve payloads or supporting files over HTTP(S) using Windows’ background transfer mechanism. It relies on BITS client telemetry, matching EventID 16403 and the RemoteName containing indicators for common file-sharing domains.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1197/T1197.md
- https://twitter.com/malmoeb/status/1535142803075960832
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
- https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/bits_client/win_bits_client_new_transfer_via_file_sharing_domains.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-06-28
modified: 2026-03-29
tags:
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1197
logsource:
product: windows
service: bits-client
detection:
selection:
EventID: 16403
RemoteName|contains:
- .githubusercontent.com
- 0x0.st
- anonfiles.com
- bashupload.com
- cdn.discordapp.com
- chunk.io
- ddns.net
- dl.dropboxusercontent.com
- ghostbin.co
- github.com
- glitch.me
- gofile.io
- hastebin.com
- mediafire.com
- mega.nz
- onrender.com
- pages.dev
- paste.ee
- pastebin.com
- pastebin.pl
- pastetext.net
- pixeldrain.com
- privatlab.com
- privatlab.net
- send.exploit.in
- sendspace.com
- storage.googleapis.com
- storjshare.io
- supabase.co
- temp.sh
- transfer.sh
- trycloudflare.com
- ufile.io
- w3spaces.com
- workers.dev
- x0.at
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags Windows BITS client activity where a BITS transfer downloads from specific file-sharing and content hosting domains. Such downloads can be used by attackers to stealthily retrieve payloads or supporting files over HTTP(S) using Windows’ background transfer mechanism. It relies on BITS client telemetry, matching EventID 16403 and the RemoteName containing indicators for common file-sharing domains.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.