avatar

doyou know

@doyouknow
Completionist
5 followers47 downloads1,087 copies75 likes30,427 views

17 detections

This rule detects potential infection by fake-VPN browser extensions associated with the 'Myxa VPN' campaign by monitoring for specific file paths and filenames linked to known malicious extension IDs. Additionally, it monitors for network connections to known command-and-control IP addresses associated with this campaign.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
2 months ago
11013
KQL Query
avatar
doyou know@doyouknow
avatar
Detections.ai Community
2 months ago
20132
This rule detects various stages of the VOID#GEIST multi-stage Python loader as described in the Securonix blog. It identifies initial batch file execution, Chrome decoy PDF lures, hidden PowerShell relaunching of the batch file, persistence via the Startup folder, curl commands downloading zip payloads, Python embedded runtime downloads, and final Python payload execution. The rule is designed to catch the distinct command-line patterns associated with each stage of this specific malware.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
7 months ago
4066
This rule detects activity related to the Chrysalis Backdoor, which is associated with the Lotus Blossom threat group. It identifies malicious activity through three main components: 1. File and process events matching a list of known malicious SHA256 hashes. 2. Network connections to known malicious IP addresses or domains. 3. Suspicious execution of 'svchost.exe' from non-standard Windows directories with specific command-line arguments, indicating potential masquerading or malicious execution.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
8 months ago
132622,615
This rule detects the presence and activity of known malicious browser extensions, specifically 'NexShield' and those associated with the 'KongTuke' campaign. It identifies these extensions by their unique IDs found in file paths or names, network connections to associated malicious IPs or domains, and specific file hashes. The rule correlates file events, network events, and process events to provide a comprehensive view of the malicious extension's activity, including when it was first and last seen, the browsers involved, and the files/folders it interacted with.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
9 months ago
10214792
This rule detects the presence or execution of known malicious infostealer files based on their SHA256 hash values or a specific filename pattern. The SHA256 hashes are associated with infostealer malware as referenced in a VirusTotal blog post. The filename pattern 'malwarebytes-windows-github-io' also indicates potential malicious activity, likely related to a deceptive download or execution.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
9 months ago
372199
This rule detects indicators associated with the 'Office Assistant' supply chain attack. It identifies malicious browser extensions by their IDs in file paths or names, and also detects known malicious file MD5s and C2 communication domains. The rule correlates file events and network events to provide a comprehensive view of the attack.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
9 months ago
541327
This rule detects activities associated with the VVS Stealer malware, as described in the Palo Alto Networks Unit 42 blog. It identifies the malware through specific SHA256 hashes of known VVS Stealer executables, network connections to hardcoded Discord webhook URLs used for exfiltration, persistence mechanisms via creation of executables in Windows startup folders, creation of '_vault.zip' files (likely containing stolen data), and suspicious Discord-related process activity indicative of the stealer's operation.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
9 months ago
676470
This rule detects the presence of known malicious browser extensions, specifically "Zoom Stealer Extension" and "Shady Panda Extension", by looking for their unique Extension IDs within file paths or file names on devices. It identifies the first and last seen timestamps, the names of the extensions, their IDs, associated campaigns, and the browsers they target, summarizing this information per device.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
9 months ago
1176862
This rule detects suspicious network connections to known malicious URLs associated with a Docker Desktop malware campaign. It also identifies instances where 'DockerDesktop.exe' is executed or present in unusual file paths, suggesting potential masquerading or unauthorized deployment outside of its standard installation directory. The rule is broken into three parts: network events, file events, and process events. The network part looks for connections to specific malicious domains. The file and process parts look for 'DockerDesktop.exe' in folders other than the assumed legitimate installation path, indicating potential malicious activity.
avatar
doyou know@doyouknow
avatar
Detections.ai Community
10 months ago
341327
Page 1 of 2