Windows BITS Client Job Downloads from Direct IP Addresses

Alerts when Windows BITS Client downloads via HTTP/HTTPS URLs containing direct IP addresses.

FreeUnreviewedSigmahighv1
title: Windows BITS Client Job Downloads from Direct IP Addresses
id: d6cd2e9b-71d7-4392-aad1-0abea6914c0a
related:
  - id: 99c840f2-2012-46fd-9141-c761987550ef
    type: similar
  - id: 90f138c1-f578-4ac3-8c49-eecfd847c8b7
    type: derived
status: test
description: This rule flags Windows BITS Client events where a BITS transfer job retrieves content from an HTTP/HTTPS URL that embeds an IP address. Direct-IP downloads are commonly used to blend in with automated transfer activity while avoiding domain-based detection. It relies on Windows BITS-Client telemetry, specifically EventID 16403, and matches on the remote URL containing common direct IP patterns while excluding several local-network and 7-zip-related cases.
references:
  - https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin
  - https://isc.sans.edu/diary/22264
  - https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/
  - https://blog.talosintelligence.com/breaking-the-silence-recent-truebot-activity/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/bits_client/win_bits_client_new_transfer_via_ip_address.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-01-11
modified: 2023-03-27
tags:
  - attack.persistence
  - attack.execution
  - attack.stealth
  - attack.t1197
logsource:
  product: windows
  service: bits-client
detection:
  selection:
    EventID: 16403
    RemoteName|contains:
      - http://1
      - http://2
      - http://3
      - http://4
      - http://5
      - http://6
      - http://7
      - http://8
      - http://9
      - https://1
      - https://2
      - https://3
      - https://4
      - https://5
      - https://6
      - https://7
      - https://8
      - https://9
  filter_optional_local_networks:
    RemoteName|contains:
      - ://10.
      - ://192.168.
      - ://172.16.
      - ://172.17.
      - ://172.18.
      - ://172.19.
      - ://172.20.
      - ://172.21.
      - ://172.22.
      - ://172.23.
      - ://172.24.
      - ://172.25.
      - ://172.26.
      - ://172.27.
      - ://172.28.
      - ://172.29.
      - ://172.30.
      - ://172.31.
      - ://127.
      - ://169.254.
  filter_optional_seven_zip:
    RemoteName|contains:
      - https://7-
      - http://7-
  condition: selection and not 1 of filter_optional_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags Windows BITS Client events where a BITS transfer job retrieves content from an HTTP/HTTPS URL that embeds an IP address. Direct-IP downloads are commonly used to blend in with automated transfer activity while avoiding domain-based detection. It relies on Windows BITS-Client telemetry, specifically EventID 16403, and matches on the remote URL containing common direct IP patterns while excluding several local-network and 7-zip-related cases.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.