Detection rules › Sigma

New Connection Initiated To Potential Dead Drop Resolver Domain

Status
test
Severity
high
Log source
category network_connection, product windows
Author
Sorina Ionescu, X__Junior (Nextron Systems)
Source
github.com/SigmaHQ/sigma

Detects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks. In this context attackers leverage known websites such as "facebook", "youtube", etc. In order to pass through undetected.

Known false positives

  • One might need to exclude other internet browsers found in it's network or other applications like ones mentioned above from Microsoft Defender.
  • Ninite contacting githubusercontent.com

MITRE ATT&CK coverage

TacticTechniques
Command & Control

Telemetry coverage

ProviderRecord / event type
SysmonEvent ID 3: Network connection

Rule body

title: New Connection Initiated To Potential Dead Drop Resolver Domain
id: 297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
related:
    - id: d7b09985-95a3-44be-8450-b6eadf49833e
      type: obsolete
    - id: 8b48ad89-10d8-4382-a546-50588c410f0d
      type: similar
    - id: d635249d-86b5-4dad-a8c7-d7272b788586
      type: similar
    - id: 52182dfb-afb7-41db-b4bc-5336cb29b464
      type: similar
    - id: ae02ed70-11aa-4a22-b397-c0d0e8f6ea99
      type: similar
    - id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
      type: similar
    - id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
      type: similar
    - id: 8518ed3d-f7c9-4601-a26c-f361a4256a0c
      type: similar
    - id: 42a5f1e7-9603-4f6d-97ae-3f37d130d794
      type: similar
    - id: 56454143-524f-49fb-b1c6-3fb8b1ad41fb
      type: similar
    - id: b6e04788-29e1-4557-bb14-77f761848ab8
      type: similar
    - id: a0d7e4d2-bede-4141-8896-bc6e237e977c
      type: similar
status: test
description: |
    Detects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks.
    In this context attackers leverage known websites such as "facebook", "youtube", etc. In order to pass through undetected.
references:
    - https://web.archive.org/web/20220830134315/https://content.fireeye.com/apt-41/rpt-apt41/
    - https://securelist.com/the-tetrade-brazilian-banking-malware/97779/
    - https://blog.bushidotoken.net/2021/04/dead-drop-resolvers-espionage-inspired.html
    - https://github.com/kleiton0x00/RedditC2
    - https://twitter.com/kleiton0x7e/status/1600567316810551296
    - https://www.linkedin.com/posts/kleiton-kurti_github-kleiton0x00redditc2-abusing-reddit-activity-7009939662462984192-5DbI/?originalSubdomain=al
author: Sorina Ionescu, X__Junior (Nextron Systems)
date: 2022-08-17
modified: 2026-03-29
tags:
    - attack.command-and-control
    - attack.t1102
    - attack.t1102.001
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Initiated: 'true'
        DestinationHostname|endswith:
            - '.t.me'
            - '0x0.st'
            - '4shared.com'
            - 'abuse.ch'
            - 'anonfiles.com'
            - 'bashupload.com'
            - 'cdn.discordapp.com'
            - 'chunk.io'
            - 'cloudflare.com'
            - 'ddns.net'
            - 'discord.com'
            - 'docs.google.com'
            - 'drive.google.com'
            - 'dropbox.com'
            - 'dropmefiles.com'
            - 'facebook.com'
            - 'feeds.rapidfeeds.com'
            - 'fotolog.com'
            - 'ghostbin.co/'
            - 'githubusercontent.com'
            - 'gofile.io'
            - 'hastebin.com'
            - 'imgur.com'
            - 'livejournal.com'
            - 'mediafire.com'
            - 'mega.co.nz'
            - 'mega.nz'
            - 'onedrive.com'
            - 'pages.dev'
            - 'paste.ee'
            - 'pastebin.com'
            - 'pastebin.pl'
            - 'pastetext.net'
            - 'pixeldrain.com'
            - 'privatlab.com'
            - 'privatlab.net'
            - 'reddit.com'
            - 'send.exploit.in'
            - 'sendspace.com'
            - 'steamcommunity.com'
            - 'storage.googleapis.com'
            - 'technet.microsoft.com'
            - 'temp.sh'
            - 'transfer.sh'
            - 'trycloudflare.com'
            - 'twitter.com'
            - 'ufile.io'
            - 'vimeo.com'
            - 'w3spaces.com'
            - 'wetransfer.com'
            - 'workers.dev'
            - 'x0.at'
            - 'youtube.com'
    # Note: Add/Remove browsers/applications that you don't use or those that have custom install locations
    # Note: To avoid complex conditions the filters for some apps are generic by name only. A custom tuning is recommended for best results
    filter_main_chrome:
        Image:
            - 'C:\Program Files\Google\Chrome\Application\chrome.exe'
            - 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe'
    filter_main_chrome_appdata:
        Image|startswith: 'C:\Users\'
        Image|endswith: '\AppData\Local\Google\Chrome\Application\chrome.exe'
    filter_main_firefox:
        Image:
            - 'C:\Program Files\Mozilla Firefox\firefox.exe'
            - 'C:\Program Files (x86)\Mozilla Firefox\firefox.exe'
    filter_main_firefox_appdata:
        Image|startswith: 'C:\Users\'
        Image|endswith: '\AppData\Local\Mozilla Firefox\firefox.exe'
    filter_main_ie:
        Image:
            - 'C:\Program Files (x86)\Internet Explorer\iexplore.exe'
            - 'C:\Program Files\Internet Explorer\iexplore.exe'
    filter_main_edge_1:
        - Image|startswith: 'C:\Program Files (x86)\Microsoft\EdgeWebView\Application\'
        - Image|endswith: '\WindowsApps\MicrosoftEdge.exe'
        - Image:
              - 'C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe'
              - 'C:\Program Files\Microsoft\Edge\Application\msedge.exe'
    filter_main_edge_2:
        Image|startswith:
            - 'C:\Program Files (x86)\Microsoft\EdgeCore\'
            - 'C:\Program Files\Microsoft\EdgeCore\'
        Image|endswith:
            - '\msedge.exe'
            - '\msedgewebview2.exe'
    filter_main_safari:
        Image|contains:
            - 'C:\Program Files (x86)\Safari\'
            - 'C:\Program Files\Safari\'
        Image|endswith: '\safari.exe'
    filter_main_defender:
        Image|contains:
            - 'C:\Program Files\Windows Defender Advanced Threat Protection\'
            - 'C:\Program Files\Windows Defender\'
            - 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
        Image|endswith:
            - '\MsMpEng.exe' # Microsoft Defender executable
            - '\MsSense.exe' # Windows Defender Advanced Threat Protection Service Executable
    filter_main_prtg:
        # Paessler's PRTG Network Monitor
        Image|endswith:
            - 'C:\Program Files (x86)\PRTG Network Monitor\PRTG Probe.exe'
            - 'C:\Program Files\PRTG Network Monitor\PRTG Probe.exe'
    filter_main_brave:
        Image|startswith: 'C:\Program Files\BraveSoftware\'
        Image|endswith: '\brave.exe'
    filter_main_maxthon:
        Image|contains: '\AppData\Local\Maxthon\'
        Image|endswith: '\maxthon.exe'
    filter_main_opera:
        Image|contains: '\AppData\Local\Programs\Opera\'
        Image|endswith: '\opera.exe'
    filter_main_seamonkey:
        Image|startswith:
            - 'C:\Program Files\SeaMonkey\'
            - 'C:\Program Files (x86)\SeaMonkey\'
        Image|endswith: '\seamonkey.exe'
    filter_main_vivaldi:
        Image|contains: '\AppData\Local\Vivaldi\'
        Image|endswith: '\vivaldi.exe'
    filter_main_whale:
        Image|startswith:
            - 'C:\Program Files\Naver\Naver Whale\'
            - 'C:\Program Files (x86)\Naver\Naver Whale\'
        Image|endswith: '\whale.exe'
    # Note: The TOR browser shouldn't be something you allow in your corporate network.
    # filter_main_tor:
    #     Image|contains: '\Tor Browser\'
    filter_main_whaterfox:
        Image|startswith:
            - 'C:\Program Files\Waterfox\'
            - 'C:\Program Files (x86)\Waterfox\'
        Image|endswith: '\Waterfox.exe'
    filter_main_midori:
        Image|contains: '\AppData\Local\Programs\midori-ng\'
        Image|endswith: '\Midori Next Generation.exe'
    filter_main_slimbrowser:
        Image|startswith:
            - 'C:\Program Files\SlimBrowser\'
            - 'C:\Program Files (x86)\SlimBrowser\'
        Image|endswith: '\slimbrowser.exe'
    filter_main_flock:
        Image|contains: '\AppData\Local\Flock\'
        Image|endswith: '\Flock.exe'
    filter_main_phoebe:
        Image|contains: '\AppData\Local\Phoebe\'
        Image|endswith: '\Phoebe.exe'
    filter_main_falkon:
        Image|startswith:
            - 'C:\Program Files\Falkon\'
            - 'C:\Program Files (x86)\Falkon\'
        Image|endswith: '\falkon.exe'
    filter_main_qtweb:
        Image|startswith:
            - 'C:\Program Files (x86)\QtWeb\'
            - 'C:\Program Files\QtWeb\'
        Image|endswith: '\QtWeb.exe'
    filter_main_avant:
        Image|startswith:
            - 'C:\Program Files (x86)\Avant Browser\'
            - 'C:\Program Files\Avant Browser\'
        Image|endswith: '\avant.exe'
    filter_main_whatsapp:
        Image|startswith:
            - 'C:\Program Files (x86)\WindowsApps\'
            - 'C:\Program Files\WindowsApps\'
        Image|endswith: '\WhatsApp.exe'
        DestinationHostname|endswith: 'facebook.com'
    filter_main_telegram:
        Image|contains: '\AppData\Roaming\Telegram Desktop\'
        Image|endswith: '\Telegram.exe'
        DestinationHostname|endswith: '.t.me'
    filter_main_onedrive:
        Image|contains: '\AppData\Local\Microsoft\OneDrive\'
        Image|endswith: '\OneDrive.exe'
        DestinationHostname|endswith: 'onedrive.com'
    filter_main_dropbox:
        Image|startswith:
            - 'C:\Program Files (x86)\Dropbox\Client\'
            - 'C:\Program Files\Dropbox\Client\'
        Image|endswith:
            - '\Dropbox.exe'
            - '\DropboxInstaller.exe'
        DestinationHostname|endswith: 'dropbox.com'
    filter_main_mega:
        Image|endswith:
            # Note: This is a basic/best effort filter in order to avoid FP with the MEGA installer and executable.
            #       In practice please apply exact path to avoid basic path bypass techniques.
            - '\MEGAsync.exe'
            - '\MEGAsyncSetup32_*RC.exe' # Beta versions
            - '\MEGAsyncSetup32.exe' # Installers 32bit
            - '\MEGAsyncSetup64.exe' # Installers 64bit
            - '\MEGAupdater.exe'
        DestinationHostname|endswith:
            - 'mega.co.nz'
            - 'mega.nz'
    filter_main_googledrive:
        Image|contains:
            - 'C:\Program Files\Google\Drive File Stream\'
            - 'C:\Program Files (x86)\Google\Drive File Stream\'
        Image|endswith: 'GoogleDriveFS.exe'
        DestinationHostname|endswith: 'drive.google.com'
    filter_main_discord:
        Image|contains: '\AppData\Local\Discord\'
        Image|endswith: '\Discord.exe'
        DestinationHostname|endswith:
            - 'discord.com'
            - 'cdn.discordapp.com'
    filter_main_null:
        Image: null
    filter_main_empty:
        Image: ''
    # filter_optional_qlik:
    #     Image|endswith: '\Engine.exe' # Process from qlik.com app
    condition: selection and not 1 of filter_main_*
falsepositives:
    - One might need to exclude other internet browsers found in it's network or other applications like ones mentioned above from Microsoft Defender.
    - Ninite contacting githubusercontent.com
level: high

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_main_*

Stage 1: selection

selection:
    Initiated: 'true'
    DestinationHostname|endswith:
        - '.t.me'
        - '0x0.st'
        - '4shared.com'
        - 'abuse.ch'
        - 'anonfiles.com'
        - 'bashupload.com'
        - 'cdn.discordapp.com'
        - 'chunk.io'
        - 'cloudflare.com'
        - 'ddns.net'
        - 'discord.com'
        - 'docs.google.com'
        - 'drive.google.com'
        - 'dropbox.com'
        - 'dropmefiles.com'
        - 'facebook.com'
        - 'feeds.rapidfeeds.com'
        - 'fotolog.com'
        - 'ghostbin.co/'
        - 'githubusercontent.com'
        - 'gofile.io'
        - 'hastebin.com'
        - 'imgur.com'
        - 'livejournal.com'
        - 'mediafire.com'
        - 'mega.co.nz'
        - 'mega.nz'
        - 'onedrive.com'
        - 'pages.dev'
        - 'paste.ee'
        - 'pastebin.com'
        - 'pastebin.pl'
        - 'pastetext.net'
        - 'pixeldrain.com'
        - 'privatlab.com'
        - 'privatlab.net'
        - 'reddit.com'
        - 'send.exploit.in'
        - 'sendspace.com'
        - 'steamcommunity.com'
        - 'storage.googleapis.com'
        - 'technet.microsoft.com'
        - 'temp.sh'
        - 'transfer.sh'
        - 'trycloudflare.com'
        - 'twitter.com'
        - 'ufile.io'
        - 'vimeo.com'
        - 'w3spaces.com'
        - 'wetransfer.com'
        - 'workers.dev'
        - 'x0.at'
        - 'youtube.com'

Stage 2: not filter_main_*

filter_main_chrome:
    Image:
        - 'C:\Program Files\Google\Chrome\Application\chrome.exe'
        - 'C:\Program Files (x86)\Google\Chrome\Application\chrome.exe'
filter_main_chrome_appdata:
    Image|startswith: 'C:\Users\'
    Image|endswith: '\AppData\Local\Google\Chrome\Application\chrome.exe'
filter_main_firefox:
    Image:
        - 'C:\Program Files\Mozilla Firefox\firefox.exe'
        - 'C:\Program Files (x86)\Mozilla Firefox\firefox.exe'
filter_main_firefox_appdata:
    Image|startswith: 'C:\Users\'
    Image|endswith: '\AppData\Local\Mozilla Firefox\firefox.exe'
filter_main_ie:
    Image:
        - 'C:\Program Files (x86)\Internet Explorer\iexplore.exe'
        - 'C:\Program Files\Internet Explorer\iexplore.exe'
filter_main_edge_1:
    - Image|startswith: 'C:\Program Files (x86)\Microsoft\EdgeWebView\Application\'
    - Image|endswith: '\WindowsApps\MicrosoftEdge.exe'
    - Image:
          - 'C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe'
          - 'C:\Program Files\Microsoft\Edge\Application\msedge.exe'
filter_main_edge_2:
    Image|startswith:
        - 'C:\Program Files (x86)\Microsoft\EdgeCore\'
        - 'C:\Program Files\Microsoft\EdgeCore\'
    Image|endswith:
        - '\msedge.exe'
        - '\msedgewebview2.exe'
filter_main_safari:
    Image|contains:
        - 'C:\Program Files (x86)\Safari\'
        - 'C:\Program Files\Safari\'
    Image|endswith: '\safari.exe'
filter_main_defender:
    Image|contains:
        - 'C:\Program Files\Windows Defender Advanced Threat Protection\'
        - 'C:\Program Files\Windows Defender\'
        - 'C:\ProgramData\Microsoft\Windows Defender\Platform\'
    Image|endswith:
        - '\MsMpEng.exe'
        - '\MsSense.exe'
filter_main_prtg:
    Image|endswith:
        - 'C:\Program Files (x86)\PRTG Network Monitor\PRTG Probe.exe'
        - 'C:\Program Files\PRTG Network Monitor\PRTG Probe.exe'
filter_main_brave:
    Image|startswith: 'C:\Program Files\BraveSoftware\'
    Image|endswith: '\brave.exe'
filter_main_maxthon:
    Image|contains: '\AppData\Local\Maxthon\'
    Image|endswith: '\maxthon.exe'
filter_main_opera:
    Image|contains: '\AppData\Local\Programs\Opera\'
    Image|endswith: '\opera.exe'
filter_main_seamonkey:
    Image|startswith:
        - 'C:\Program Files\SeaMonkey\'
        - 'C:\Program Files (x86)\SeaMonkey\'
    Image|endswith: '\seamonkey.exe'
filter_main_vivaldi:
    Image|contains: '\AppData\Local\Vivaldi\'
    Image|endswith: '\vivaldi.exe'
filter_main_whale:
    Image|startswith:
        - 'C:\Program Files\Naver\Naver Whale\'
        - 'C:\Program Files (x86)\Naver\Naver Whale\'
    Image|endswith: '\whale.exe'
filter_main_whaterfox:
    Image|startswith:
        - 'C:\Program Files\Waterfox\'
        - 'C:\Program Files (x86)\Waterfox\'
    Image|endswith: '\Waterfox.exe'
filter_main_midori:
    Image|contains: '\AppData\Local\Programs\midori-ng\'
    Image|endswith: '\Midori Next Generation.exe'
filter_main_slimbrowser:
    Image|startswith:
        - 'C:\Program Files\SlimBrowser\'
        - 'C:\Program Files (x86)\SlimBrowser\'
    Image|endswith: '\slimbrowser.exe'
filter_main_flock:
    Image|contains: '\AppData\Local\Flock\'
    Image|endswith: '\Flock.exe'
filter_main_phoebe:
    Image|contains: '\AppData\Local\Phoebe\'
    Image|endswith: '\Phoebe.exe'
filter_main_falkon:
    Image|startswith:
        - 'C:\Program Files\Falkon\'
        - 'C:\Program Files (x86)\Falkon\'
    Image|endswith: '\falkon.exe'
filter_main_qtweb:
    Image|startswith:
        - 'C:\Program Files (x86)\QtWeb\'
        - 'C:\Program Files\QtWeb\'
    Image|endswith: '\QtWeb.exe'
filter_main_avant:
    Image|startswith:
        - 'C:\Program Files (x86)\Avant Browser\'
        - 'C:\Program Files\Avant Browser\'
    Image|endswith: '\avant.exe'
filter_main_whatsapp:
    Image|startswith:
        - 'C:\Program Files (x86)\WindowsApps\'
        - 'C:\Program Files\WindowsApps\'
    Image|endswith: '\WhatsApp.exe'
    DestinationHostname|endswith: 'facebook.com'
filter_main_telegram:
    Image|contains: '\AppData\Roaming\Telegram Desktop\'
    Image|endswith: '\Telegram.exe'
    DestinationHostname|endswith: '.t.me'
filter_main_onedrive:
    Image|contains: '\AppData\Local\Microsoft\OneDrive\'
    Image|endswith: '\OneDrive.exe'
    DestinationHostname|endswith: 'onedrive.com'
filter_main_dropbox:
    Image|startswith:
        - 'C:\Program Files (x86)\Dropbox\Client\'
        - 'C:\Program Files\Dropbox\Client\'
    Image|endswith:
        - '\Dropbox.exe'
        - '\DropboxInstaller.exe'
    DestinationHostname|endswith: 'dropbox.com'
filter_main_mega:
    Image|endswith:
        - '\MEGAsync.exe'
        - '\MEGAsyncSetup32_*RC.exe'
        - '\MEGAsyncSetup32.exe'
        - '\MEGAsyncSetup64.exe'
        - '\MEGAupdater.exe'
    DestinationHostname|endswith:
        - 'mega.co.nz'
        - 'mega.nz'
filter_main_googledrive:
    Image|contains:
        - 'C:\Program Files\Google\Drive File Stream\'
        - 'C:\Program Files (x86)\Google\Drive File Stream\'
    Image|endswith: 'GoogleDriveFS.exe'
    DestinationHostname|endswith: 'drive.google.com'
filter_main_discord:
    Image|contains: '\AppData\Local\Discord\'
    Image|endswith: '\Discord.exe'
    DestinationHostname|endswith:
        - 'discord.com'
        - 'cdn.discordapp.com'
filter_main_null:
    Image: null
filter_main_empty:
    Image: ''

Exclusions

The rule actively suppresses these predicates.

FieldKindExcluded valuesSearch
DestinationHostnameends_withcdn.discordapp.comexcludes:DestinationHostname field:"DestinationHostname" value:"cdn.discordapp.com"
DestinationHostnameends_withdiscord.comexcludes:DestinationHostname field:"DestinationHostname" value:"discord.com"
Imageends_with\Discord.exeexcludes:Image field:"Image" value:"\Discord.exe"
Imagematch\AppData\Local\Discord\excludes:Image field:"Image" value:"\AppData\Local\Discord\"
DestinationHostnameends_withmega.co.nzexcludes:DestinationHostname field:"DestinationHostname" value:"mega.co.nz"
DestinationHostnameends_withmega.nzexcludes:DestinationHostname field:"DestinationHostname" value:"mega.nz"
Imageends_with\MEGAsync.exeexcludes:Image field:"Image" value:"\MEGAsync.exe"
Imageends_with\MEGAsyncSetup32.exeexcludes:Image field:"Image" value:"\MEGAsyncSetup32.exe"
Imageends_with\MEGAsyncSetup32_*RC.exeexcludes:Image field:"Image" value:"\MEGAsyncSetup32_*RC.exe"
Imageends_with\MEGAsyncSetup64.exeexcludes:Image field:"Image" value:"\MEGAsyncSetup64.exe"
Imageends_with\MEGAupdater.exeexcludes:Image field:"Image" value:"\MEGAupdater.exe"
Imageends_with\Dropbox.exeexcludes:Image field:"Image" value:"\Dropbox.exe"
Imageends_with\DropboxInstaller.exeexcludes:Image field:"Image" value:"\DropboxInstaller.exe"
Imagestarts_withC:\Program Files (x86)\Dropbox\Client\excludes:Image field:"Image" value:"C:\Program Files (x86)\Dropbox\Client\"
Imagestarts_withC:\Program Files\Dropbox\Client\excludes:Image field:"Image" value:"C:\Program Files\Dropbox\Client\"
DestinationHostnameends_withdropbox.comexcludes:DestinationHostname field:"DestinationHostname" value:"dropbox.com"
Imageends_with\MsMpEng.exeexcludes:Image field:"Image" value:"\MsMpEng.exe"
Imageends_with\MsSense.exeexcludes:Image field:"Image" value:"\MsSense.exe"
ImagematchC:\Program Files\Windows Defender Advanced Threat Protection\excludes:Image field:"Image" value:"C:\Program Files\Windows Defender Advanced Threat Protection\"
ImagematchC:\Program Files\Windows Defender\excludes:Image field:"Image" value:"C:\Program Files\Windows Defender\"
ImagematchC:\ProgramData\Microsoft\Windows Defender\Platform\excludes:Image field:"Image" value:"C:\ProgramData\Microsoft\Windows Defender\Platform\"
Imageends_with\msedge.exeexcludes:Image field:"Image" value:"\msedge.exe"
Imageends_with\msedgewebview2.exeexcludes:Image field:"Image" value:"\msedgewebview2.exe"
Imagestarts_withC:\Program Files (x86)\Microsoft\EdgeCore\excludes:Image field:"Image" value:"C:\Program Files (x86)\Microsoft\EdgeCore\"
Imagestarts_withC:\Program Files\Microsoft\EdgeCore\excludes:Image field:"Image" value:"C:\Program Files\Microsoft\EdgeCore\"
ImagematchC:\Program Files (x86)\Google\Drive File Stream\excludes:Image field:"Image" value:"C:\Program Files (x86)\Google\Drive File Stream\"
ImagematchC:\Program Files\Google\Drive File Stream\excludes:Image field:"Image" value:"C:\Program Files\Google\Drive File Stream\"
DestinationHostnameends_withdrive.google.comexcludes:DestinationHostname field:"DestinationHostname" value:"drive.google.com"
Imageends_withGoogleDriveFS.exeexcludes:Image field:"Image" value:"GoogleDriveFS.exe"
ImagematchC:\Program Files (x86)\Safari\excludes:Image field:"Image" value:"C:\Program Files (x86)\Safari\"
ImagematchC:\Program Files\Safari\excludes:Image field:"Image" value:"C:\Program Files\Safari\"
Imageends_with\safari.exeexcludes:Image field:"Image" value:"\safari.exe"
Imagestarts_withC:\Program Files (x86)\Avant Browser\excludes:Image field:"Image" value:"C:\Program Files (x86)\Avant Browser\"
Imagestarts_withC:\Program Files\Avant Browser\excludes:Image field:"Image" value:"C:\Program Files\Avant Browser\"
Imageends_with\avant.exeexcludes:Image field:"Image" value:"\avant.exe"
Imagestarts_withC:\Program Files (x86)\Falkon\excludes:Image field:"Image" value:"C:\Program Files (x86)\Falkon\"
Imagestarts_withC:\Program Files\Falkon\excludes:Image field:"Image" value:"C:\Program Files\Falkon\"
Imageends_with\falkon.exeexcludes:Image field:"Image" value:"\falkon.exe"
Imagestarts_withC:\Program Files (x86)\Naver\Naver Whale\excludes:Image field:"Image" value:"C:\Program Files (x86)\Naver\Naver Whale\"
Imagestarts_withC:\Program Files\Naver\Naver Whale\excludes:Image field:"Image" value:"C:\Program Files\Naver\Naver Whale\"
Imageends_with\whale.exeexcludes:Image field:"Image" value:"\whale.exe"
Imagestarts_withC:\Program Files (x86)\QtWeb\excludes:Image field:"Image" value:"C:\Program Files (x86)\QtWeb\"
Imagestarts_withC:\Program Files\QtWeb\excludes:Image field:"Image" value:"C:\Program Files\QtWeb\"
Imageends_with\QtWeb.exeexcludes:Image field:"Image" value:"\QtWeb.exe"
Imagestarts_withC:\Program Files (x86)\SeaMonkey\excludes:Image field:"Image" value:"C:\Program Files (x86)\SeaMonkey\"
Imagestarts_withC:\Program Files\SeaMonkey\excludes:Image field:"Image" value:"C:\Program Files\SeaMonkey\"
Imageends_with\seamonkey.exeexcludes:Image field:"Image" value:"\seamonkey.exe"
Imagestarts_withC:\Program Files (x86)\SlimBrowser\excludes:Image field:"Image" value:"C:\Program Files (x86)\SlimBrowser\"
Imagestarts_withC:\Program Files\SlimBrowser\excludes:Image field:"Image" value:"C:\Program Files\SlimBrowser\"
Imageends_with\slimbrowser.exeexcludes:Image field:"Image" value:"\slimbrowser.exe"
Imagestarts_withC:\Program Files (x86)\Waterfox\excludes:Image field:"Image" value:"C:\Program Files (x86)\Waterfox\"
Imagestarts_withC:\Program Files\Waterfox\excludes:Image field:"Image" value:"C:\Program Files\Waterfox\"
Imageends_with\Waterfox.exeexcludes:Image field:"Image" value:"\Waterfox.exe"
Imagestarts_withC:\Program Files (x86)\WindowsApps\excludes:Image field:"Image" value:"C:\Program Files (x86)\WindowsApps\"
Imagestarts_withC:\Program Files\WindowsApps\excludes:Image field:"Image" value:"C:\Program Files\WindowsApps\"
DestinationHostnameends_withfacebook.comexcludes:DestinationHostname field:"DestinationHostname" value:"facebook.com"
Imageends_with\WhatsApp.exeexcludes:Image field:"Image" value:"\WhatsApp.exe"
DestinationHostnameends_with.t.meexcludes:DestinationHostname field:"DestinationHostname" value:".t.me"
Imageends_with\Telegram.exeexcludes:Image field:"Image" value:"\Telegram.exe"
Imagematch\AppData\Roaming\Telegram Desktop\excludes:Image field:"Image" value:"\AppData\Roaming\Telegram Desktop\"
DestinationHostnameends_withonedrive.comexcludes:DestinationHostname field:"DestinationHostname" value:"onedrive.com"
Imageends_with\OneDrive.exeexcludes:Image field:"Image" value:"\OneDrive.exe"
Imagematch\AppData\Local\Microsoft\OneDrive\excludes:Image field:"Image" value:"\AppData\Local\Microsoft\OneDrive\"
Imageends_with\AppData\Local\Google\Chrome\Application\chrome.exeexcludes:Image field:"Image" value:"\AppData\Local\Google\Chrome\Application\chrome.exe"
Imagestarts_withC:\Users\excludes:Image field:"Image" value:"C:\Users\"
Imageends_with\AppData\Local\Mozilla Firefox\firefox.exeexcludes:Image field:"Image" value:"\AppData\Local\Mozilla Firefox\firefox.exe"
Imageends_with\Flock.exeexcludes:Image field:"Image" value:"\Flock.exe"
Imagematch\AppData\Local\Flock\excludes:Image field:"Image" value:"\AppData\Local\Flock\"
Imageends_with\Midori Next Generation.exeexcludes:Image field:"Image" value:"\Midori Next Generation.exe"
Imagematch\AppData\Local\Programs\midori-ng\excludes:Image field:"Image" value:"\AppData\Local\Programs\midori-ng\"
Imageends_with\Phoebe.exeexcludes:Image field:"Image" value:"\Phoebe.exe"
Imagematch\AppData\Local\Phoebe\excludes:Image field:"Image" value:"\AppData\Local\Phoebe\"
Imageends_with\brave.exeexcludes:Image field:"Image" value:"\brave.exe"
Imagestarts_withC:\Program Files\BraveSoftware\excludes:Image field:"Image" value:"C:\Program Files\BraveSoftware\"
Imageends_with\maxthon.exeexcludes:Image field:"Image" value:"\maxthon.exe"
Imagematch\AppData\Local\Maxthon\excludes:Image field:"Image" value:"\AppData\Local\Maxthon\"
Imageends_with\opera.exeexcludes:Image field:"Image" value:"\opera.exe"
Imagematch\AppData\Local\Programs\Opera\excludes:Image field:"Image" value:"\AppData\Local\Programs\Opera\"
Imageends_with\vivaldi.exeexcludes:Image field:"Image" value:"\vivaldi.exe"
Imagematch\AppData\Local\Vivaldi\excludes:Image field:"Image" value:"\AppData\Local\Vivaldi\"
Imageends_withC:\Program Files (x86)\PRTG Network Monitor\PRTG Probe.exeexcludes:Image field:"Image" value:"C:\Program Files (x86)\PRTG Network Monitor\PRTG Probe.exe"
Imageends_withC:\Program Files\PRTG Network Monitor\PRTG Probe.exeexcludes:Image field:"Image" value:"C:\Program Files\PRTG Network Monitor\PRTG Probe.exe"
Imageends_with\WindowsApps\MicrosoftEdge.exeexcludes:Image field:"Image" value:"\WindowsApps\MicrosoftEdge.exe"
ImageeqC:\Program Files (x86)\Google\Chrome\Application\chrome.exeexcludes:Image field:"Image" value:"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
ImageeqC:\Program Files (x86)\Internet Explorer\iexplore.exeexcludes:Image field:"Image" value:"C:\Program Files (x86)\Internet Explorer\iexplore.exe"
ImageeqC:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeexcludes:Image field:"Image" value:"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"
ImageeqC:\Program Files (x86)\Mozilla Firefox\firefox.exeexcludes:Image field:"Image" value:"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
ImageeqC:\Program Files\Google\Chrome\Application\chrome.exeexcludes:Image field:"Image" value:"C:\Program Files\Google\Chrome\Application\chrome.exe"
ImageeqC:\Program Files\Internet Explorer\iexplore.exeexcludes:Image field:"Image" value:"C:\Program Files\Internet Explorer\iexplore.exe"
ImageeqC:\Program Files\Microsoft\Edge\Application\msedge.exeexcludes:Image field:"Image" value:"C:\Program Files\Microsoft\Edge\Application\msedge.exe"
ImageeqC:\Program Files\Mozilla Firefox\firefox.exeexcludes:Image field:"Image" value:"C:\Program Files\Mozilla Firefox\firefox.exe"
Imageis_null(no value, null check)excludes:Image
Imagestarts_withC:\Program Files (x86)\Microsoft\EdgeWebView\Application\excludes:Image field:"Image" value:"C:\Program Files (x86)\Microsoft\EdgeWebView\Application\"

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
DestinationHostnameends_with
  • .t.me
  • 0x0.st corpus 2 (sigma 2)
  • 4shared.com
  • abuse.ch
  • anonfiles.com corpus 2 (sigma 2)
  • bashupload.com corpus 2 (sigma 2)
  • cdn.discordapp.com corpus 2 (sigma 2)
  • chunk.io corpus 2 (sigma 2)
  • cloudflare.com
  • ddns.net corpus 2 (sigma 2)
  • discord.com
  • docs.google.com
  • drive.google.com
  • dropbox.com
  • dropmefiles.com
  • facebook.com
  • feeds.rapidfeeds.com
  • fotolog.com
  • ghostbin.co/
  • githubusercontent.com
  • gofile.io corpus 2 (sigma 2)
  • hastebin.com corpus 2 (sigma 2)
  • imgur.com
  • livejournal.com
  • mediafire.com corpus 2 (sigma 2)
  • mega.co.nz corpus 3 (sigma 3)
  • mega.nz corpus 3 (sigma 3)
  • onedrive.com
  • pages.dev corpus 2 (sigma 2)
  • paste.ee corpus 2 (sigma 2)
  • pastebin.com corpus 2 (sigma 2)
  • pastebin.pl corpus 2 (sigma 2)
  • pastetext.net corpus 2 (sigma 2)
  • pixeldrain.com corpus 2 (sigma 2)
  • privatlab.com corpus 2 (sigma 2)
  • privatlab.net corpus 2 (sigma 2)
  • reddit.com
  • send.exploit.in corpus 2 (sigma 2)
  • sendspace.com corpus 2 (sigma 2)
  • steamcommunity.com
  • storage.googleapis.com corpus 2 (sigma 2)
  • technet.microsoft.com
  • temp.sh corpus 2 (sigma 2)
  • transfer.sh corpus 2 (sigma 2)
  • trycloudflare.com corpus 3 (sigma 3)
  • twitter.com
  • ufile.io corpus 2 (sigma 2)
  • vimeo.com
  • w3spaces.com corpus 2 (sigma 2)
  • wetransfer.com
  • workers.dev corpus 2 (sigma 2)
  • x0.at corpus 2 (sigma 2)
  • youtube.com
field:"DestinationHostname" kind:ends_with
Initiatedeq
  • true corpus 50 (sigma 50)
field:"Initiated" kind:eq value:"true"