• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    SilverFox Relay/Dispatch Infrastructure Domain Communication

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•3

    Detects DNS queries, HTTP host headers, and TLS SNI traffic associated with the SilverFox relay and dispatch infrastructure. These indicators are commonly used by the SilverFox malware for command and control (C2) communications.

    Suricata

    Tags

    T1071.001 - Web ProtocolsT1105 - Ingress Tool TransferT1583.006 - Web ServicesDNS QueryHTTP RequestNetwork Connection OutboundNetwork GenericSuricata IDSSnort IDSDNSTrojan Activity

    Found in

    • SilverFox Evolves Delivery Mechanisms via Cloud Blacklist LogicLast updated 25 days ago
    • SilverFox Evolves Delivery Mechanisms via Cloud Blacklist LogicLast updated 25 days ago
    • SilverFox Evolves Delivery Mechanisms via Cloud Blacklist LogicLast updated 25 days ago
    • SilverFox Evolves Delivery Mechanisms via Cloud Blacklist LogicLast updated 25 days ago
    • SilverFox Evolves Delivery Mechanisms via Cloud Blacklist LogicLast updated 25 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?