
Arnold Chan
@slazTrusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,559 views
7,082 detections
Filters
Last updated
All Time
Detection languages
5,288
907
382
169
98
Categories
2,255
1,689
1,128
920
811
Platforms
3,924
1,476
1,096
648
634
Products / Services
2,609
904
892
690
476
MITRE Techniques
2,008
1,469
1,358
1,002
499
CVEs
38
33
24
22
21
IDS Classtypes
422
155
96
79
52
IDS Protocols
495
136
136
78
18
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
