• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Connection to Malicious Converter App Domains

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Lewis Weedon@LewisWeedon
    •updated Feb 2, 2026•53•5•472

    This rule detects network connections to domains known to host and distribute malicious file converter applications that install Remote Access Trojans (RATs).

    Microsoft Sentinel (KQL)

    Tags

    T1105 - Ingress Tool TransferT1219 - Remote Access ToolsTA0011 - Command and ControlNetwork ConnectionMalware DetectedWindowsWindows Defender Atpkql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?