
doyou know
@doyouknowCompletionist
5 followers47 downloads1,087 copies75 likes30,427 views
17 detections
Filters
Last updated
All Time
Detection languages
17
Categories
9
9
8
4
4
Platforms
14
2
1
1
Products / Services
13
MITRE Techniques
9
9
5
4
4
This rule detects potential infection by fake-VPN browser extensions associated with the 'Myxa VPN' campaign by monitoring for specific file paths and filenames linked to known malicious extension IDs. Additionally, it monitors for network connections to known command-and-control IP addresses associated with this campaign.
KQL Query
This rule detects various stages of the VOID#GEIST multi-stage Python loader as described in the Securonix blog. It identifies initial batch file execution, Chrome decoy PDF lures, hidden PowerShell relaunching of the batch file, persistence via the Startup folder, curl commands downloading zip payloads, Python embedded runtime downloads, and final Python payload execution. The rule is designed to catch the distinct command-line patterns associated with each stage of this specific malware.
This rule detects activity related to the Chrysalis Backdoor, which is associated with the Lotus Blossom threat group. It identifies malicious activity through three main components: 1. File and process events matching a list of known malicious SHA256 hashes. 2. Network connections to known malicious IP addresses or domains. 3. Suspicious execution of 'svchost.exe' from non-standard Windows directories with specific command-line arguments, indicating potential masquerading or malicious execution.
This rule detects the presence and activity of known malicious browser extensions, specifically 'NexShield' and those associated with the 'KongTuke' campaign. It identifies these extensions by their unique IDs found in file paths or names, network connections to associated malicious IPs or domains, and specific file hashes. The rule correlates file events, network events, and process events to provide a comprehensive view of the malicious extension's activity, including when it was first and last seen, the browsers involved, and the files/folders it interacted with.
This rule detects the presence or execution of known malicious infostealer files based on their SHA256 hash values or a specific filename pattern. The SHA256 hashes are associated with infostealer malware as referenced in a VirusTotal blog post. The filename pattern 'malwarebytes-windows-github-io' also indicates potential malicious activity, likely related to a deceptive download or execution.
This rule detects indicators associated with the 'Office Assistant' supply chain attack. It identifies malicious browser extensions by their IDs in file paths or names, and also detects known malicious file MD5s and C2 communication domains. The rule correlates file events and network events to provide a comprehensive view of the attack.
vvs-stealer
KQL
This rule detects activities associated with the VVS Stealer malware, as described in the Palo Alto Networks Unit 42 blog. It identifies the malware through specific SHA256 hashes of known VVS Stealer executables, network connections to hardcoded Discord webhook URLs used for exfiltration, persistence mechanisms via creation of executables in Windows startup folders, creation of '_vault.zip' files (likely containing stolen data), and suspicious Discord-related process activity indicative of the stealer's operation.
This rule detects the presence of known malicious browser extensions, specifically "Zoom Stealer Extension" and "Shady Panda Extension", by looking for their unique Extension IDs within file paths or file names on devices. It identifies the first and last seen timestamps, the names of the extensions, their IDs, associated campaigns, and the browsers they target, summarizing this information per device.
This rule detects suspicious network connections to known malicious URLs associated with a Docker Desktop malware campaign. It also identifies instances where 'DockerDesktop.exe' is executed or present in unusual file paths, suggesting potential masquerading or unauthorized deployment outside of its standard installation directory. The rule is broken into three parts: network events, file events, and process events. The network part looks for connections to specific malicious domains. The file and process parts look for 'DockerDesktop.exe' in folders other than the assumed legitimate installation path, indicating potential malicious activity.
Page 1 of 2
