Borrowed Trust link99: Non-browser outbound connection to hijacked subdomain or Hong Kong backend fleet
This rule detects suspicious network connections to known infrastructure associated with the 'Borrowed Trust' gambling kit. It identifies connections to specific IP addresses, IP ranges, compromised subdomains, URLs containing affiliate referrer codes, known redirect destinations, and a unique favicon path. The rule specifically excludes connections originating from common browser processes to focus on non-browser initiated activity, which could indicate malware or other malicious software attempting to establish C2 or exfiltrate data.
Microsoft Sentinel (KQL)

