Skip to content
Threat Feed
high advisory

Suspicious Linux Outbound Connections to Bulletproof Hosting ASNs

This detection logic identifies outbound network connections from Linux hosts originating from anomalous locations or via suspicious binaries to ASNs associated with bulletproof or high-abuse hosting providers.

This threat brief describes detection logic aimed at identifying command-and-control (C2) activity and staging of payloads within Linux environments. Adversaries frequently leverage high-abuse or bulletproof hosting providers, such as Storm Industries, Ecatel, Aeza, and Proton66, to host malicious infrastructure that ignores abuse reports. The detection focuses on outbound connections triggered by living-off-the-land (LotL) binaries (e.g., curl, wget, python, or various shell interpreters) or processes executing from non-standard, world-writable, or web-accessible directories such as /tmp, /dev/shm, /var/www, and memfd. This activity is often a strong indicator of initial payload retrieval, webshell operation, or persistent C2 beaconing. Defenders should validate that outbound traffic to these specific high-risk ASNs aligns with approved administrative or business requirements, as many of these providers lack robust abuse-handling policies.

Impact

Successful exploitation of these patterns can lead to unauthorized remote command execution, persistent backdoor access, exfiltration of sensitive data, or the deployment of secondary malicious payloads. Compromise of Linux systems, particularly those exposed to the internet, may result in widespread network traversal or the conversion of the host into a node for further malicious operations, with potential damage to system integrity and data confidentiality.

Recommendation

  • Enable comprehensive network and process-creation logging to identify outbound connections from non-standard directories.
  • Implement and tune the provided detection logic to monitor traffic destined for high-abuse ASNs.
  • Investigate any process initiated from /tmp, /var/tmp, or web directories that maintains persistent connections to unknown external IP addresses.
  • Block identified high-abuse ASNs at the network perimeter (DNS, firewall, proxy) where business operations permit.
  • Conduct regular audits of public-facing web directories to identify and remove unauthorized webshells or staged ELF binaries.

Immediate actions

Deploy and tune the detection rule to match your known-good infrastructure.

Detection Engineering 48h

Threat Hunt

Identify all processes executing from /tmp, /var/tmp, or web directories that have initiated network connections.

T1059 high high confidence hunt now

Data: Process creation logs, Network connection logs

Detection coverage 1

Suspicious Linux Process Connection to Bulletproof Hosting ASN

high

Detects outbound connection attempts from unusual Linux process locations or common living-off-the-land utilities to ASNs associated with bulletproof or high-abuse hosting.

sigma tactics: command_and_control techniques: T1071 sources: network_connection, linux

Detection queries are available on the platform. Get full rules →