avatar

Lewis Weedon

@LewisWeedon
Completionist
1 follower11 downloads420 copies30 likes2,572 views

5 detections

This rule detects potential phishing activity by correlating email delivery of Excel attachments with subsequent network connections to known malicious domains initiated by common browser or office processes. It identifies cases where a user may have opened a suspicious Excel file and initiated an outbound network request to a flagged domain within 24 hours of receiving the email.
avatar
Lewis Weedon@LewisWeedon
avatar
Detections.ai Community
1 month ago
762158
EvilAi Campaign
avatar
Lewis Weedon@LewisWeedon
avatar
Aruga Cyber
4 months ago
13040
This rule detects file and network indicators of compromise (IOCs) associated with the fake 'ClawdBot Agent' VS Code extension malware campaign. It looks for known malicious file hashes and network connections to C2 infrastructure, including specific C2 checks for ScreenConnect relay on port 8041.
avatar
Lewis Weedon@LewisWeedon
avatar
Aruga Cyber
8 months ago
229211,523
This rule detects network connections to domains known to host and distribute malicious file converter applications that install Remote Access Trojans (RATs).
avatar
Lewis Weedon@LewisWeedon
avatar
Aruga Cyber
8 months ago
535472
This rule detects outbound network connections to command and control (C2) domains and identifies files by name or hash associated with malicious PDF editor campaigns (e.g., ConvertMate, PDFClick, PDFSkills). These campaigns use malicious PDF editors for C2 communication, to download additional payloads, and for initial execution.
avatar
Lewis Weedon@LewisWeedon
avatar
Aruga Cyber
8 months ago
492379