Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

5 detections

Detects HTTP requests to known Storm-2755 Payroll Pirates AiTM lookalike proxy domains that also reference Microsoft authentication infrastructure in the URI, indicating a reverse-proxy phishing kit relaying to real Microsoft login endpoints.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
0011
Detects DNS queries to Google Ads click-tracking infrastructure followed within 60 seconds by resolution of a newly registered, previously unseen domain, consistent with the Storm-2755 AiTM redirect chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
106
Detects POST requests to the Storm-2755 Payroll Pirates AiTM toolkit fingerprinting endpoint URI pattern co-occurring with the distinctive openresty/PHP response header combination.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects the Payroll Pirates (Storm-2755) AiTM phishing redirect chain: Google Meet/Ads redirector, an AWS S3 intermediate hop, and final resolution of a previously-unseen domain, indicating completion of the multi-hop chain to an AiTM proxy.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
804
Detects AiTM phishing page geolocation fingerprint script referencing api.country.is, setting an rcfh_country cookie, and redirecting via oauth2/v2.0/authorize.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103