
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,566 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
Detects a multi-stage process execution chain involving PowerShell: first, a script-based download of remote content, followed by in-memory reflection, and finally, suspicious memory allocation or thread manipulation within the same process context. This pattern is characteristic of fileless malware execution chains designed to evade disk-based detection.
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
