Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

11 detections

Detects Linux persistence and removal activity by the botking implant, systemd user-service creation with the 'System Config User Service' description marker, secondary symlink persistence, or systemctl --user enable/disable for install/removal.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
5020
Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
108
Detects the Rust rustls custom AcceptAll ServerCertVerifier pattern (all three verify methods returning success unconditionally) used by the proc-macro1 payload to bypass TLS certificate validation when fetching its remote payload.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects known malicious stage-2 payload binaries dropped by the compromised proc-macro1/arrayref Rust supply-chain attack via hash, size, and file-type match.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects binaries embedding both the hardcoded AES-128-GCM key 'i am botking' and the embedded RSA-2048 private key used for C2 command authentication
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects Antino's abuse of trusted cloud services — Microsoft Graph API and Google Docs — as C2 channels, gated on non-standard TLS ports, missing browser User-Agent, and non-HTML response bodies to reduce false positives from the very high volume of legitimate traffic to these domains.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects mshta.exe execution combined with CSIS geopolitical lure content or the known TEST.hta downloader artifact used to deliver the Antino backdoor
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects cmd.exe spawned by the Jewelbug native-messaging helper registered under the Microsoft-masquerading name com.microsoft.runedge, correlated with creation of the corresponding Chrome NativeMessagingHosts registry key — the mechanism the group uses to bridge its malicious 'PDF Viewer' browser extension to an interactive remote shell.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects ClientKing's technique of loading Linux kernel modules directly from memory (via memfd/init_module) without a corresponding on-disk .ko file, used to deploy rootkit functionality.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects obfuscated JavaScript payload generated via the XG-Web code-generation platform and hosted on typosquatted fonts.tarotfree101.top domain, used by Jewelbug
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects fake Adobe Flash/Adobe installer executables used by Jewelbug to drop the Antino backdoor, sideload slc.dll, install the 'PDF Viewer' extension, and register the com.microsoft.runedge native-messaging helper. Requires known filenames combined with known hashes or slc.dll/indicator strings, and excludes files carrying a valid Adobe code-signing certificate.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
201