Windows BITS Client Downloads From File-Sharing Domains

Alerts on Windows BITS transfers (EventID 16403) that download from known file-sharing/content hosting domains.

FreeReviewedSigma · High · v2
Product
windows
Service
bits-client
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-06-28
Updated
2026-07-31
title: Windows BITS Client Downloads From File-Sharing Domains
id: 4f091046-0675-4655-860c-2410db4a1d20
related:
  - id: 8b48ad89-10d8-4382-a546-50588c410f0d
    type: similar
  - id: 52182dfb-afb7-41db-b4bc-5336cb29b464
    type: similar
  - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
    type: similar
  - id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
    type: similar
  - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
    type: similar
  - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
    type: similar
  - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
    type: similar
  - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
    type: similar
  - id: b6e04788-29e1-4557-bb14-77f761848ab8
    type: similar
  - id: a0d7e4d2-bede-4141-8896-bc6e237e977c
    type: similar
  - id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
    type: similar
  - id: d635249d-86b5-4dad-a8c7-d7272b788586
    type: derived
status: test
description: This rule identifies Windows BITS client activity where a BITS transfer job downloads a file from a remote name associated with common file-sharing or hosting domains. Attackers can abuse BITS to stealthily retrieve payloads or scripts while blending into legitimate background download behavior. The detection relies on BITS client telemetry recording EventID 16403 along with the remote host name matched against a set of known domain patterns.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1197/T1197.md
  - https://twitter.com/malmoeb/status/1535142803075960832
  - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
  - https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/bits_client/win_bits_client_new_transfer_via_file_sharing_domains.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2022-06-28
modified: 2026-03-29
tags:
  - attack.persistence
  - attack.execution
  - attack.stealth
  - attack.t1197
logsource:
  product: windows
  service: bits-client
detection:
  selection:
    EventID: 16403
    RemoteName|contains:
      - .githubusercontent.com
      - 0x0.st
      - anonfiles.com
      - bashupload.com
      - cdn.discordapp.com
      - chunk.io
      - ddns.net
      - dl.dropboxusercontent.com
      - ghostbin.co
      - github.com
      - glitch.me
      - gofile.io
      - hastebin.com
      - mediafire.com
      - mega.nz
      - onrender.com
      - pages.dev
      - paste.ee
      - pastebin.com
      - pastebin.pl
      - pastetext.net
      - pixeldrain.com
      - privatlab.com
      - privatlab.net
      - send.exploit.in
      - sendspace.com
      - storage.googleapis.com
      - storjshare.io
      - supabase.co
      - temp.sh
      - transfer.sh
      - trycloudflare.com
      - ufile.io
      - w3spaces.com
      - workers.dev
      - x0.at
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1