• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    KREMLIN known-IOC sweep: domains and file hashes

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 24 days ago•0•0•2

    This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.

    Microsoft Sentinel (KQL)

    Tags

    T1059 - Command and Scripting InterpreterT1566 - PhishingTA0002 - ExecutionNetwork Connection OutboundFile Executable DetectedProcess CreationWindowsWindows Defender Atpkql

    Found in

    • KREMLIN Banking Malware Hijacks Chromium BrowsersLast updated 24 days ago
    • KREMLIN Banking Malware Hijacks Chromium BrowsersLast updated 24 days ago
    • KREMLIN Banking Malware Hijacks Chromium BrowsersLast updated 24 days ago
    • KREMLIN Banking Malware Hijacks Chromium BrowsersLast updated 24 days ago
    • KREMLIN Banking Malware Hijacks Chromium BrowsersLast updated 24 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?