Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

12 detections

Detects outbound C2 connections to known ACRStealer infrastructure IPs specifically from a process already flagged as hollowed/injected (wab.exe, MSBuild.exe, dllhost.exe) via a companion flowbit, rather than flagging all egress from these processes.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
008
Detects ACRStealer C2 data-transfer bursts (outbound credential-data exfiltration >100KB, inbound follow-on payload >1MB) correlated with prior credential-sweep and process-injection-stage flowbits, rather than raw transfer size alone.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a malformed/high-entropy repeated-label DNS query pattern used by ACRStealer as a connectivity canary check prior to establishing C2.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects the ACRStealer Telegram Dead Drop Resolver handoff: a non-Telegram-client TLS/SNI contact into Telegram's IP range immediately followed by a DNS/TLS/HTTP connection to the resolved C2 domain res.explicittweak.cc.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects the fake Adobe Flash update download from microsoft-flash[.]com/download/Adobeinstall.exe, served only after Jewelbug's 'flash' module validates the victim's targeted domain, account status, and OS.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
007
Detects XG-Web implant check-in beacons — DNS lookups and HTTP config_*.js fetches — against Jewelbug's typosquatted C2 domain set, the unified panel reported to have logged over one million implant check-ins.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects a ClientKing-style beacon abusing internal proxy CONNECT authentication to reach known Jewelbug C2 infrastructure (tarotfree101.top), reusing a compromised organization's own proxy the way Jewelbug reused a major aerospace manufacturer's internal proxy.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects Antino's abuse of trusted cloud services — Microsoft Graph API and Google Docs — as C2 channels, gated on non-standard TLS ports, missing browser User-Agent, and non-HTML response bodies to reduce false positives from the very high volume of legitimate traffic to these domains.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects the exact watering-hole script fetch (fonts.chrorne[.]com /dist/js/*.chunk.js) injected into shared government webmail installations, which opens a WebSocket back to Jewelbug C2 and exfiltrates session cookies and usernames.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
004
Detects DNS queries and HTTP traffic to Jewelbug's known typosquatted C2 domains (fonts.chrorne[.]com, fonts.tarotfree101[.]top, robot.avbliud[.]com, www.f1ash[.]org[.]cn) via exact-match logic to avoid fuzzy-matching false positives.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects ClientKing's custom DNS-tunneling C2 channel via high-entropy, long subdomains in TXT-record queries at sustained volume.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects TLS SNI and HTTP Host values matching Jewelbug's typosquatted-domain pattern impersonating the OKX and Binance cryptocurrency exchanges, used to drive traffic to cloaked phishing pages.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002