avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,490 copies160 likes51,999 views

8,664 detections

This rule detects the presence of Phoenix malware by identifying known SHA256 hashes of its components or network connections to its command and control (C2) infrastructure. It correlates file events with known malware hashes and network events with known C2 IP addresses.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Correlates phishing email delivery with subsequent communication to attacker-controlled domains.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects processes making HTTP/HTTPS requests to localhost on ports 40341 or 40342 for '/metadata'. This pattern can indicate local service discovery, inter-process communication, or potentially malicious activity attempting to interact with local services, possibly for credential access or privilege escalation.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
202
Detects suspicious payload execution or unexpected child processes spawning directly from the IIS worker process (w3wp.exe), which is a common indicator of web shell activity or exploit payload execution on vulnerable IIS instances.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects execution of the malicious miner components associated with the Hola Browser supply-chain compromise. Researchers identified me.exe and HolaMonitorService.exe as unauthorized payloads bundled with affected installations.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects a Python process spawning curl to make outbound web requests. This behavior aligns with the PoC for CVE-2026-4372 (HuggingFace Transformers RCE), where Python sub-processes curl to exfiltrate credentials.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects the creation of the specific PoC proof file (/tmp/hf_rce_poc_proof.txt) generated by the CVE-2026-4372 exploit payload targeting the HuggingFace Transformers library.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Identifies device code sign-ins originating from infrastructure previously associated with phishing operations and adversary-controlled relay servers.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
102
Detects emails matching the Microsoft-reported AiTM phishing campaign that used Code of Conduct review lures and PDF attachments.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002
Detects RuntimeHost.exe launched from an unusual cache directory frequently associated with malware staging and cryptomining activity.
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
002