• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    BabylonRAT HOSTS File Modification for Traffic Redirection

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•4

    Detects unauthorized write, create, or rename operations on the Windows HOSTS file (\drivers\etc\hosts). The rule excludes common system processes and paths associated with legitimate administrative or update activities, targeting potentially malicious attempts to redirect network traffic by modifying DNS resolution locally.

    Cortex XDR

    Tags

    T1565.001 - Stored Data ManipulationTA0040 - ImpactFile ModificationFile CreationFile RenameWindows

    Found in

    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago
    • BabylonRAT Malware Analysis and Technical OverviewLast updated 22 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?