
doyou know
@doyouknowCompletionist
5 followers47 downloads1,087 copies75 likes30,427 views
17 detections
Filters
Last updated
All Time
Detection languages
17
Categories
9
9
8
4
4
Platforms
14
2
1
1
Products / Services
13
MITRE Techniques
9
9
5
4
4
This rule detects the presence and activity of the ShadyPanda malware campaign, specifically focusing on malicious Chrome extensions and their associated command and control (C2) and data exfiltration domains. It identifies the creation of files with known malicious Chrome extension IDs (ending in '.crx') and network connections to hardcoded C2 and exfiltration domains linked to the ShadyPanda campaign.
This rule set detects several indicators of compromise related to the Shai-Hulud threat activity. It identifies specific malicious file hashes (SHA256) for 'bundle.js' files, the execution of the 'trufflehog' tool which is often abused for secrets discovery, the presence of a malicious YAML file named 'shai-hulud-workflow.yml', and network connections to 'webhook.site' domains, optionally with a specific URI, which are used for data exfiltration or command and control.
KQL Query from file: ConvertMate - suspicious PDF editor
IOCs and behavior from Danabot version 669
Detects the LANDFALL Android spyware manipulating SELinux policy by preloading a malicious shared object and passing a path to the 'l.so' policy manipulator component via the PRELOAD_PATH environment variable.
Detects network connections to known Command and Control (C2) servers associated with the LANDFALL Android spyware. The spyware communicates over HTTPS, often on non-standard ports.
KQL Query from file: Powershell History Logging Disabled KQL
Page 2 of 2
