T1496.002 IBM QRadar · QRadar

Detect Bandwidth Hijacking in IBM QRadar

Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. This includes proxyjacking (selling victim bandwidth and IP address to proxyware services such as Honeygain, IPRoyal Pawns, Peer2Profit, PacketStream, and Traffmonetizer), participating in botnets for network denial of service campaigns, seeding malicious torrents, and conducting internet-wide scanning using victim systems. Proxyware agents installed on victim machines route third-party traffic through the victim's IP address, generating revenue for the adversary while consuming the victim's bandwidth and potentially implicating the victim's IP in illegal activity.

MITRE ATT&CK

Tactic
Impact
Technique
T1496 Resource Hijacking
Sub-technique
T1496.002 Bandwidth Hijacking
Canonical reference
https://attack.mitre.org/techniques/T1496/002/

QRadar Detection Query

IBM QRadar (QRadar)
sql
SELECT
  DATEFORMAT(starttime, 'yyyy-MM-dd HH:mm:ss') AS event_time,
  sourceip AS src_ip,
  destinationip AS dst_ip,
  destinationport AS dst_port,
  username,
  LOGSOURCENAME(logsourceid) AS log_source,
  CATEGORYNAME(category) AS category_name,
  QIDNAME(qid) AS event_name,
  "FileName" AS process_name,
  "CommandLine" AS command_line,
  "ParentImage" AS parent_process,
  "DestinationHostname" AS dst_hostname,
  CASE
    WHEN LOWER("FileName") MATCHES '(honeygain(\.exe|client\.exe)?|iproyal.desktop\.exe|iproyal_desktop\.exe|pawns\.exe|peer2profit\.exe|p2p-node\.exe|packetstream\.exe|psnode\.exe|traffmonetizer\.exe|traffmain\.exe|earnapp\.exe|repocket\.exe|bitping\.exe|mysterium\.exe|myst\.exe)'
      THEN 'KnownProxywareBinary'
    WHEN LOWER("DestinationHostname") MATCHES '(honeygain|iproyal|pawns\.app|peer2profit|packetstream|traffmonetizer|earnapp|repocket|bitping|mysterium\.network)'
      THEN 'ProxywareDomainConnection'
    ELSE 'Unknown'
  END AS detection_branch
FROM events
WHERE (
  LOGSOURCETYPENAME(devicetype) ILIKE '%sysmon%'
  OR LOGSOURCETYPENAME(devicetype) ILIKE '%windows%'
)
AND (
  LOWER("FileName") MATCHES '(honeygain|iproyal.desktop|iproyal_desktop|pawns\.exe|peer2profit|p2p-node|packetstream|psnode|traffmonetizer|traffmain|earnapp|repocket|bitping|mysterium|myst\.exe)'
  OR LOWER("DestinationHostname") MATCHES '(honeygain|iproyal|pawns\.app|peer2profit|packetstream|traffmonetizer|earnapp|repocket|bitping|mysterium\.network)'
)
LAST 24 HOURS
ORDER BY event_time DESC
high severity high confidence

Detects proxyware binary execution and outbound network connections to known bandwidth-hijacking service domains using QRadar custom properties populated from Sysmon (EventCode 1 and 3) or Windows Security event logs.

Data Sources

IBM QRadar SIEMSysmon DSM via Windows Event LogMicrosoft Windows Security Event Log DSM

Required Tables

events

False Positives & Tuning

  • Employees who have installed personal proxyware applications on company endpoints prior to policy enforcement or security tool rollout
  • Security operations teams running proxyware samples inside QRadar-monitored sandboxed virtual machines during threat intelligence exercises
  • Custom internal network relay or proxy tools whose binary names or destination hostnames partially match the detection patterns
Download portable Sigma rule (.yml)

Other platforms for T1496.002


Testing Methodology

Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Honeygain Proxyware Agent Binary Simulation (Windows)

    Expected signal: Sysmon Event ID 11: File Create — honeygain.exe written to %APPDATA%. Sysmon Event ID 1: Process Create — Image path ends with 'honeygain.exe' in AppData directory, ParentImage=cmd.exe. Security Event ID 4688 (if command line auditing enabled): ProcessName contains honeygain.exe.

  2. Test 2Proxyware Registry Run Key Persistence (Windows)

    Expected signal: Sysmon Event ID 13: Registry Value Set — TargetObject=HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Honeygain, Details containing '%APPDATA%\honeygain.exe --token=SIM_TOKEN_12345'. Security Event ID 4657 if registry object access auditing is enabled.

  3. Test 3High-Volume External Connection Simulation (Windows)

    Expected signal: Sysmon Event ID 3: Approximately 80 Network Connection events from powershell.exe to diverse external IPs (8.8.*.1 range) on port 80, appearing within a short time window. DeviceNetworkEvents in MDE will show InitiatingProcessFileName=powershell.exe with high UniqueRemoteIPs count.

  4. Test 4Proxyware Domain DNS Resolution (Linux)

    Expected signal: Sysmon for Linux Event ID 22: DNS Query events for honeygain.com, peer2profit.com, packetstream.io, traffmonetizer.com, earnapp.com. Process audit records for 'host' command execution. Network captures (if packet capture enabled) show DNS queries to these domains from the host's public IP.

Unlock Pro Content

Get the full detection package for T1496.002 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections