Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects HTTP POST tasking check-ins to /version/check.php using the backdoor's hardcoded, obsolete Chrome 78.0.3904.108 user-agent string.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a DNS query for diagrtrack.com, a typosquat of Windows DiagTrack registered to serve as this backdoor's C2 infrastructure (dormant since early 2021).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects a 32-byte ICMP echo request carrying the backdoor's 8-byte bot ID, explicitly excluding the standard Windows ping.exe payload pattern (the dominant legitimate traffic at this size) and rate-limited to reduce alert volume.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001