Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

14 detections

This rule detects artifacts and behaviors associated with the WaterPlum/Contagious Interview (also known as DeceptiveDevelopment) malware suite, including BeaverTail, InvisibleFerret, and related payloads. The rule specifically targets the presence of embedded family-name strings, as well as the execution of suspicious npm package installations triggered by VS Code task automation (tasks.json) or trust prompts, common in fake technical interview attack scenarios.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
005
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
003
Detects Node.js or Python processes exhibiting suspicious behavior consistent with information-stealing malware (such as BeaverTail or InvisibleFerret). The rule monitors for these processes accessing sensitive files, including browser credentials, cookies, browser extension wallet settings, cryptocurrency wallet files, and various identification document image types, followed by the execution of archiving utilities (e.g., zip, rar, 7z) to stage the collected data for exfiltration.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
103
Detects malicious software bundles consistent with the Contagious Interview (G1052) threat group's multi-stage infection chain. The rule identifies the presence of multiple malware family identifiers (such as BeaverTail, InvisibleFerret, and others) within the context of npm or VS Code task configuration files, which are commonly used in job-assessment themed social engineering campaigns.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
16 days ago
002
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
003
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
002
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
19 days ago
002
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
002
Detects outbound TLS traffic behavior consistent with the WaterPlum RAT, characterized by periodic, low-volume connections to non-CDN/cloud providers. The rule identifies potential beaconing activity by monitoring TLS SNI fields against a list of known legitimate service providers and applying a frequency threshold.
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Hunters
19 days ago
001
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
19 days ago
001
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
19 days ago
001
Detects BeaverTail malware deployed via PurpleDelta/PurpleBravo coordination; requires multiple occurrences of the distinctive BeaverTail string to reduce false positives
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
007