avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,566 views

7,082 detections

This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
5 days ago
001
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
000
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
avatar
Arnold Chan@slaz
Defender - KQL
3 days ago
000
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
000
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
000
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
avatar
Arnold Chan@slaz
Defender - KQL
3 days ago
000
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
000
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
000