Title:
TeamViewer Domain Query By Non-TeamViewer Application
Status:
test
Description:Detects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
References:
-https://www.teamviewer.com/en-us/
Author: Florian Roth (Nextron Systems)
Date: 2022-01-30
modified:2023-09-18
Tags:
- -'attack.command-and-control'
- -'attack.t1219.002'
Logsource:
- product: windows
- category: dns_query
Detection:
selection:
QueryName:
-'taf.teamviewer.com'
-'udp.ping.teamviewer.com'
filter_main_teamviewer:
Image|contains:
'TeamViewer'
condition:
selection and not 1 of filter_main_*
Falsepositives:
-Unknown binary names of TeamViewer
-Depending on the environment the rule might require some initial tuning before usage to avoid FP with third party applications
Level:
medium