Operation DragonReturn DcRAT C2 Beaconing - Port 2671 and Known IPs/Domains
Detects network activity associated with the DcRAT trojan as identified in Operation DragonReturn. This includes outbound network connections to hardcoded C2 port 2671, connections to known malicious IP addresses, and DNS resolutions of identified attacker-controlled C2 domains.
SentinelOne

