FORENSIA

ATT&CK · T1197

BITS Jobs

Tactics: stealth, persistence, execution

About

Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications. File transfer tasks are implemented as BITS jobs, which contain a queue of one or more file operations. The interface to create and manage BITS jobs is accessible through PowerShell and the BITSAdmin tool. Adversaries may abuse BITS to download (e.g. Ingress Tool Transfer), execute, and even clean up after running malicious code (e.g. Indicator Removal). BITS tasks are self-contained in the BITS job database, without new files or registry modifications, and often permitted by host firewalls. BITS enabled execution may also enable persistence by creating long-standing jobs (the default maximum lifetime is 90 days and extendable) or invoking an arbitrary program when a job completes or errors (including after system reboots). BITS upload functionalities can also be used to perform Exfiltration Over Alternative Protocol.

Platforms: WindowsMITRE ATT&CK ↗

Used by actors

5 known groups

Software

8 malware/tools implement this

Cobalt StrikeBITSAdminJPINUBoatRATBazarEgregorMarkiRATProLock

Corpus indicators tagged with this technique

85 indicators in the corpus carry T1197.

IndicatorTypeFamilySevSrc
fa246327bed8fc5864827a8147b8b7aedb6246068259b8c97e82adb957315347sha256801
bb0c7ae4f12e5141480ee26f473636b07e836bb994ff3b2cfec93d4480da171bsha256801
13440348516ccee839675f6ac908dd1724ce1d28f92af92fdc7938740d2b7ec5sha256801
66dcd98c6b310f4429890821e609d48cc6395a6be15ffe5a121ec68b7a8f7402sha256801
ea755862ee81dd0d991b4afca42d8b82bb22a8f1d370bf3d28dbf2e44ab241ddsha256801
400eb6a94810323a1fc5f8ab31c682fe765aaec2cc61b37c31d719c7e45c9a6csha256801
a4f1b79e96a7d016de1991a64506792018de99eac5df00f7cabe26ef41b2bd81sha256801
51a6686b8c5ec7c610637398f3de43589f4e9fcbe8bcc0245343c5454d3b91desha256801
6c74d29903bc2cc17ec4afdb1a120d2060209b22830cee2b7005f5436e86f90esha256801
3b172281f65ceaee280ae810edb6fd39a1ecd25649f929f246c0405df94f4c89sha256801
cc59bf019af195dcec4394ffd7a8e23c080f4e02b12dcb7c04fb1da6671922a1sha256801
f7bde19f9e085650378076dabac586dcdc256e743a57890000e71a7ebb43d8eesha256801
8a7f5c8533df9e51b2da7cc2aeb52d8787418e4915577cc9288be1e46d1945c6sha256801
4186e41a8d6ae3b316174fc601e418b8e2a664b6sha1781
8179539efdb90eab355667ac7683358741c8a8ecsha1781
40513398ae248c87f46b13b7f9f303e05d018472sha1781
c14dc6f17099a9505a2c303f204a4554a5cc219fsha1781
3fe1fcc2a21e4bab144da57ea6d0f13ddb9819e0sha1781
1c841649189a46806084b189f50300e36c423163sha1781
42c83fbfb4299202c91b3391ace6e7732f77a602sha1781
07d1db998e4dacc6777f1c854b3ab605md5761
db6bc0e947acba379e540349f74fc6eemd5761
d66de5d6dbcb6f460ae6240de8b7aab0md5761
d151ad777bcf1b3205273ab732c0fad6md5761
b56a18df4daf038785891f33c3e89489md5761
3c1f7d9d157c38d17a44f62b6560d3b4md5761
https://vip.yeplayer.store/files/yeplayer.rarurl751
89.144.145.237ip701
46.30.191.123ip701
45.86.162.197ip701

Showing the top 30 by severity of 85.