Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

8 detections

Detects PureLogs Stealer payload binaries by identifying specific artifacts including a hardcoded nibble-decoding alphabet, minimal PE imports, and high-entropy sections containing obfuscated Windows API strings like GetProcAddress, kernel32.dll, and ntdll.dll.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects DCRCVDrv.sys driver used in ACRStealer BYOVD campaign via attacker-specific hashes, certificate serial, or atypical staging path; vendor metadata and PDB are supportive only
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
002
Detects ELF binaries embedding the ClientKing implant name alongside structural indicators (Rust runtime markers or C2 configuration patterns), associated with Jewelbug espionage tooling targeting Linux servers and routers
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects mshta.exe execution combined with CSIS geopolitical lure content or the known TEST.hta downloader artifact used to deliver the Antino backdoor
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects run.pyw wrapper scripts embedding RC4-encrypted RAT blob with key-schedule byte pattern and ChaCha20 decryption routine with constant signature, for EtherHiding C2 config, used by DeviceManager RAT
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects obfuscated JavaScript payload generated via the XG-Web code-generation platform and hosted on typosquatted fonts.tarotfree101.top domain, used by Jewelbug
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
001
Detects the IntelSoftwareUpdaterV8.exe installer masquerading as a legitimate updater, bundling Python 3.11 runtime and dropping to Microsoft-looking WindowsApps path used by UNC5142 DeviceManager RAT
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
000