avatar

Arnold Chan

@slaz
Trusted contributorCompletionist
2 followers1,903 downloads3,100 copies41 likes15,559 views

7,082 detections

Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
000
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
000
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
000
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
000
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
3 days ago
000
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
3 days ago
000
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000
This rule detects anomalous GET requests to PHP files within the WordPress themes directory that match the specific pattern used by the DragonForce threat actor for secondary C2 beaconing. The detection identifies requests that lack typical WordPress request indicators like cookies or specific form fields, suggesting non-browser, programmatically generated C2 traffic.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
3 days ago
000
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
avatar
Arnold Chan@slaz
avatar
Hunters
3 days ago
000