• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    ARToken docviewer lure on workers.dev serving Cloudflare Turnstile gate

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 13 days ago•0•0•3

    This rule detects network traffic patterns associated with the ARToken phishing campaign, specifically identifying access to lure pages hosted on 'workers.dev' domains with 'docviewer' in the hostname and 'turnstile' challenge responses in the HTTP body, which is used for anti-analysis/evasion.

    Suricata

    Tags

    T1648 - Serverless ExecutionT1497 - Virtualization/Sandbox EvasionTA0002 - ExecutionTA0005 - StealthTA0007 - DiscoveryNetwork Connection OutboundHTTP RequestHTTP ResponseIDS IPS AlertNetwork GenericServerlessSuricata IDSSnort IDSHTTPWeb Application Attack

    Found in

    • ARToken Device Code Phishing for Microsoft 365Last updated 18 days ago
    • ARToken Device Code Phishing for Microsoft 365Last updated 18 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?