Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

4 detections

Detects HTTP requests to the attacker's WebApp-Form-Host operator panel managing compromised WordPress sites at scale (wp-uploading.php/wp-verifyup.php with activator parameters).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
009
Detects HTTP requests to StopAndProtect's WordPress webshells and malicious MU-plugin backdoor endpoints.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects HTTP traffic to StopAndProtect's compromised-WordPress C2 operational endpoints, heartbeat beaconing, encrypted-archive exfiltration, and victim data directory access.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects SilentDataCollector uploading AES-CBC encrypted, specifically-named archives (desktop_files, pass_V, wallet_V, filelist.zip.encrypted, documents<n>.zip) to the compromised WordPress C2.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000