• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    ChatGPT Custom GPT ClickFix campaign IOC Hunt (hashes/IP/domain/URL)

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 7 days ago•3•0•3

    This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.

    Microsoft Sentinel (KQL)

    Tags

    T1059 - Command and Scripting InterpreterT1204 - User ExecutionT1566 - PhishingTA0002 - ExecutionMalware DetectedFile Executable DetectedNetwork Connection OutboundDNS QueryFile DownloadWindowsWindows Defender Atpkql

    Found in

    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 6 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 7 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 7 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 7 days ago
    • Adversaries Abuse ChatGPT Custom GPTs for ClickFix InfectionsLast updated 7 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?