Windows Pingback backdoor via ICMP C2 using updata.exe command-line parameters
Flags Windows process creation where updata.exe spawns msdtc config start auto commands consistent with Pingback backdoor.
- Product
- windows
- Category
- process_creation
- Author
- Bhabesh Raj (SigmaHQ), DRL 1.1
- Published
- 2021-05-05
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule matches process creation events where the parent process image ends with \updata.exe and the command line contains all of the specified strings related to Pingback backdoor configuration and startup behavior. Such activity is important because it can indicate establishment of covert command-and-control functionality using ICMP tunneling. It relies on Windows process creation telemetry with access to the parent image path and full command line.
Reporting behind it
- trustwave.comhttps://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel
- app.any.runhttps://app.any.run/tasks/4a54c651-b70b-4b72-84d7-f34d301d6406
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Malware/Pingback/proc_creation_win_malware_pingback_backdoor.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Pingback backdoor via ICMP C2 using updata.exe command-line parameters
id: b96160e4-c42a-4a76-ba36-7004ef00475d
related:
- id: 35a7dc42-bc6f-46e0-9f83-81f8e56c8d4b
type: similar
- id: 2bd63d53-84d4-4210-80ff-bf0658f1bf78
type: similar
- id: b2400ffb-7680-47c0-b08a-098a7de7e7a9
type: derived
status: test
description: This rule matches process creation events where the parent process image ends with \updata.exe and the command line contains all of the specified strings related to Pingback backdoor configuration and startup behavior. Such activity is important because it can indicate establishment of covert command-and-control functionality using ICMP tunneling. It relies on Windows process creation telemetry with access to the parent image path and full command line.
references:
- https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/backdoor-at-the-end-of-the-icmp-tunnel
- https://app.any.run/tasks/4a54c651-b70b-4b72-84d7-f34d301d6406
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Malware/Pingback/proc_creation_win_malware_pingback_backdoor.yml
author: Bhabesh Raj, Huntrule Team
date: 2021-05-05
modified: 2023-02-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
- detection.emerging-threats
logsource:
product: windows
category: process_creation
detection:
selection:
ParentImage|endswith: \updata.exe
CommandLine|contains|all:
- config
- msdtc
- start
- auto
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1