avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,583 views

7,082 detections

This rule performs a retrospective sweep for indicators of compromise (IOCs) associated with the DragonForce TURN/MQTT campaign, as detailed in Lab52 threat research. It monitors for file and process activity matching known malicious hashes, as well as network connections to specific domains and URLs associated with the campaign's command-and-control infrastructure.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
000
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
000
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
000
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000
Detects anomalous HTTP GET requests to the Microsoft Teams trap-exp/tokens endpoint that do not carry the expected 'Teams' user-agent string. This pattern is indicative of the DragonForce backdoor attempting to illicitly request Skype authentication tokens.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
000
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
5 days ago
001
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
000
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
000
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000
Detects specific markers in UDP traffic on ports 3478, 5349, and 443 that are associated with the DragonForce malware's TRN1 C2 beaconing protocol. The rules identify session initiation, task polling, task acknowledgment, and result uploading behaviors.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
000