{"id":"5c84856b-55a5-45f1-826f-13f37250cf4e","title":"Malware User Agent","description":"Detects suspicious user agent strings used by malware in proxy logs","author":"Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2017-07-08","modified":"2024-04-14","tags":["attack.command-and-control","attack.t1071.001"],"technique_ids":["T1071.001"],"logsource":{"category":"proxy"},"falsepositives":["Unknown"],"references":["http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-user_agents.rules","http://www.botopedia.org/search?searchword=scan&searchphrase=all","https://networkraptor.blogspot.com/2015/01/user-agent-strings.html","https://perishablepress.com/blacklist/ua-2013.txt","https://www.bluecoat.com/en-gb/security-blog/2015-05-05/know-your-agents","https://twitter.com/kladblokje_88/status/1614673320124743681?s=12&t=joEpeVa5d58aHYNGA_To7Q","https://pbs.twimg.com/media/FtYbfsDXoAQ1Y8M?format=jpg&name=large","https://twitter.com/crep1x/status/1635034100213112833"],"source_path":"rules/web/proxy_generic/proxy_ua_malware.yml","source_sha256":"532035a4b8c7f1c588fc54f2981897adbf7f0bbf2a45a8372f137c15c9664e9f","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/web/proxy_generic/proxy_ua_malware.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Malware User Agent\nid: 5c84856b-55a5-45f1-826f-13f37250cf4e\nstatus: test\ndescription: Detects suspicious user agent strings used by malware in proxy logs\nreferences:\n    - http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-user_agents.rules\n    - http://www.botopedia.org/search?searchword=scan&searchphrase=all\n    - https://networkraptor.blogspot.com/2015/01/user-agent-strings.html\n    - https://perishablepress.com/blacklist/ua-2013.txt\n    - https://www.bluecoat.com/en-gb/security-blog/2015-05-05/know-your-agents\n    - https://twitter.com/kladblokje_88/status/1614673320124743681?s=12&t=joEpeVa5d58aHYNGA_To7Q\n    - https://pbs.twimg.com/media/FtYbfsDXoAQ1Y8M?format=jpg&name=large\n    - https://twitter.com/crep1x/status/1635034100213112833\nauthor: Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)\ndate: 2017-07-08\nmodified: 2024-04-14\ntags:\n    - attack.command-and-control\n    - attack.t1071.001\nlogsource:\n    category: proxy\ndetection:\n    selection:\n        c-useragent:\n            # RATs\n            - 'Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Chrome /53.0' # DragonOK\n            - 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1)' # Used by PlugX - base-lining recommended - https://community.rsa.com/thread/185439\n            - 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0)' # Used by PlugX - base-lining recommended - https://community.rsa.com/thread/185439\n            - 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR  1.1.4322)' # Used by PlugX - old - https://unit42.paloaltonetworks.com/unit-42-identifies-new-dragonok-backdoor-malware-deployed-against-japanese-targets/\n            - 'HttpBrowser/1.0' # HTTPBrowser RAT\n            - '*<|>*' # Houdini / Iniduoh / njRAT\n            - 'nsis_inetc (mozilla)' # ZeroAccess\n            - 'Wget/1.9+cvs-stable (Red Hat modified)' # Dyre / Upatre\n            # Ghost419 https://www.mcafee.com/blogs/other-blogs/mcafee-labs/gold-dragon-widens-olympics-malware-attacks-gains-permanent-presence-on-victims-systems/\n            - 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; .NET CLR 1.1.4322)'\n            # Malware\n            - '*zeroup*' # W32/Renos.Downloader\n            - 'Mozilla/5.0 (Windows NT 5.1 ; v.*' # Kazy\n            - '* adlib/*'\n            - '* tiny' # Trojan Downloader\n            - '* BGroom *' # Trojan Downloader\n            - '* changhuatong'\n            - '* CholTBAgent'\n            - 'Mozilla/5.0 WinInet'\n            - 'RookIE/1.0'\n            - 'M' # HkMain\n            - 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)' # Egamipload - old UA - probable prone to false positives\n            - 'Mozilla/4.0 (compatible;MSIE 7.0;Windows NT 6.0)' # Yakes\n            - 'backdoorbot'\n            - 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30731)' # Sality\n            - 'Opera/8.81 (Windows NT 6.0; U; en)' # Sality\n            - 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.1 (.NET CLR 3.5.30729)' # Sality\n            - 'Opera' # Trojan Keragany\n            - 'Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)' # Fareit\n            - 'Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)' # Webshell's back connect\n            - 'MSIE' # Toby web shell\n            - '*(Charon; Inferno)' # Loki Bot\n            - 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/5.0)' # Fareit / Pony\n            - 'Mozilla/4.0 (compatible; MSIE 6.1; Windows NT)' # https://www.virustotal.com/gui/file/8abbef8e58f012d45a7cb46c3c2729dcd33cf53e721ff8c59e238862aa0a9e0e/detection\n            - 'Mozilla/4.0(compatible; MSIE 6.0; Windows NT 5.1)' # MacControl malware https://www.virustotal.com/gui/file/d60f61f1f03a5011a0240694e110c6d370bf68a92753093186c6d14e26a15428/detection https://www.symantec.com/connect/blogs/osxmacontrol-back-it-again\n            - 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)' # used by Zebrocy malware https://app.any.run/tasks/7d7fa4a0-6970-4428-828b-29572abf9ceb/\n            # Ursnif\n            - 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 10.0; Win64; x64)'\n            - 'Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64)'\n            # Emotet\n            - 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; InfoPath.3)' # https://twitter.com/webbthewombat/status/1225827092132179968\n            # Lockbit (https://twitter.com/kladblokje_88/status/1614673320124743681?s=12&t=joEpeVa5d58aHYNGA_To7Q)\n            - 'Mozilla/5.0 (Windows NT 6.1)'\n            - 'AppleWebkit/587.38 (KHTML, like Gecko)'\n            - 'Chrome/91.0.4472.77'\n            - 'Safari/537.36'\n            - 'Edge/91.0.864.37'\n            - 'Firefox/89.0'\n            - 'Gecko/20100101'\n            # Others\n            - '* pxyscand*'\n            - '* asd'\n            - '* mdms'\n            - 'sample'\n            - 'nocase'\n            - 'Moxilla'\n            - 'Win32 *'\n            - '*Microsoft Internet Explorer*'\n            - 'agent *'\n            - 'AutoIt' # Suspicious - base-lining recommended\n            - 'IczelionDownLoad'\n            - 'Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 10.0; .NET4.0C; .NET4.0E; Tablet PC 2.0)' # https://unit42.paloaltonetworks.com/thor-plugx-variant/\n            - 'record' # https://blog.sekoia.io/raccoon-stealer-v2-part-1-the-return-of-the-dead/\n            - 'mozzzzzzzzzzz' # https://blog.sekoia.io/raccoon-stealer-v2-part-1-the-return-of-the-dead/\n            - 'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:76.0) Gecko/20100101 Firefox/76.0' # Quasar RAT UA https://twitter.com/malmoeb/status/1559994820692672519?s=20&t=g3tkNL09dZZWbFN10qDVjg\n            - 'Havana/0.1' # https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update\n            - 'antSword/v2.1' # AntSword Webshell UA\n            - 'rqwrwqrqwrqw'  # Racoon Stealer\n            - 'qwrqrwrqwrqwr'  # Racoon Stealer\n            - 'rc2.0/client'  # Racoon Stealer\n            - 'TakeMyPainBack'  # Racoon Stealer\n            - 'xxx' # Racoon Stealer\n            - '20112211' # Racoon Stealer\n            - '23591' # Racoon Stealer\n            - '901785252112' # Racoon Stealer\n            - '1235125521512' # Racoon Stealer\n            - '125122112551' # Racoon Stealer\n            - 'B1D3N_RIM_MY_ASS' # Racoon Stealer\n            - 'AYAYAYAY1337' # Racoon Stealer\n            - 'iMightJustPayMySelfForAFeature' # Racoon Stealer\n            - 'ForAFeature' # Racoon Stealer\n            - 'Ares_ldr_v_*' # AresLoader\n            # - 'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:106.0) Gecko/20100101 Firefox/106' # seen used by AresLoader\n            - 'Microsoft Internet Explorer' # https://github.com/silence-is-best/c2db\n            - 'CLCTR' # https://github.com/silence-is-best/c2db\n            - 'uploader' # https://github.com/silence-is-best/c2db\n            - 'agent' # https://github.com/silence-is-best/c2db\n            - 'License' # https://github.com/silence-is-best/c2db\n            - 'vb wininet' # https://github.com/silence-is-best/c2db\n            - 'Client' # https://github.com/silence-is-best/c2db\n            - 'Lilith-Bot/3.0' # Lilith Stealer - https://twitter.com/suyog41/status/1558051450797690880\n            - 'svc/1.0' # SVC Loader - https://twitter.com/suyog41/status/1558051450797690880\n            - 'WSHRAT' # WSHRAT - https://twitter.com/suyog41/status/1558051450797690880\n            - 'ZeroStresser Botnet/1.5' # Zerobot - https://twitter.com/suyog41/status/1558051450797690880\n            - 'OK' # Nymaim - https://twitter.com/suyog41/status/1558051450797690880\n            - 'Project1sqlite' # DarkCloud - https://twitter.com/suyog41/status/1558051450797690880\n            - 'Project1' # DarkCloud - https://twitter.com/suyog41/status/1558051450797690880\n            - 'DuckTales' # Racoon Stealer\n            - 'Zadanie' # Racoon Stealer\n            - 'GunnaWunnaBlueTips' # Racoon Stealer\n            - 'Xlmst' # Racoon Stealer\n            - 'GeekingToTheMoon' # Racoon Stealer\n            - 'SunShineMoonLight' # Racoon Stealer\n            - 'BunnyRequester' # BunnyStealer\n            - 'BunnyTasks' # BunnyStealer\n            - 'BunnyStealer' # BunnyStealer\n            - 'BunnyLoader_Dropper' # BunnyStealer\n            - 'BunnyLoader' # BunnyStealer\n            - 'BunnyShell' # BunnyStealer\n            - 'SPARK-COMMIT' # SparkRAT - https://arcticwolf.com/resources/blog/tellmethetruth-exploitation-of-cve-2023-46604-leading-to-ransomware/\n            - '4B4DB4B3' # B4B3RAT - https://twitter.com/naumovax/status/1718956514491130301\n            - 'SouthSide' # Racoon Stealer\n            - 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1)' # Latrodectus loader\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1071.001","id":"T1071.001","name":"Web Protocols","page":"techniques/enterprise/T1071.001/"}],"data_path":"data/detection-rules/5c84856b-55a5-45f1-826f-13f37250cf4e.json","kind":"sigma"}
