Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
3
Platforms
3
Products / Services
10,371
9,516
6,509
4,371
3,687
MITRE Techniques
3
2
1
1
1
IDS Classtypes
3
IDS Protocols
1
1
1
Detects HTTP POST tasking check-ins to /version/check.php using the backdoor's hardcoded, obsolete Chrome 78.0.3904.108 user-agent string.
Detects a DNS query for diagrtrack.com, a typosquat of Windows DiagTrack registered to serve as this backdoor's C2 infrastructure (dormant since early 2021).
Detects a 32-byte ICMP echo request carrying the backdoor's 8-byte bot ID, explicitly excluding the standard Windows ping.exe payload pattern (the dominant legitimate traffic at this size) and rate-limited to reduce alert volume.
