Potentially Suspicious Malware Callback Communication - Linux

 Original Source: [Sigma source]
Title: Potentially Suspicious Malware Callback Communication - Linux
Status: test
Description:Detects programs that connect to known malware callback ports based on threat intelligence reports.
References:
  -https://www.mandiant.com/resources/blog/triton-actor-ttp-profile-custom-attack-tools-detections
  -https://www.mandiant.com/resources/blog/ukraine-and-sandworm-team
  -https://www.elastic.co/guide/en/security/current/potential-non-standard-port-ssh-connection.html
  -https://thehackernews.com/2024/01/systembc-malwares-c2-server-analysis.html
  -https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors
Author: hasselj
Date: 2024-05-10
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.command-and-control'
  • -'attack.t1571'
Logsource:
  • category: network_connection
  • product: linux
Detection:
  selection:
    Initiated: 'true'
    DestinationPort:
      -'888'
      -'999'
      -'2200'
      -'2222'
      -'4000'
      -'4444'
      -'6789'
      -'8531'
      -'50501'
      -'51820'

  filter_main_local_ranges:
    DestinationIp|cidr:
      -'127.0.0.0/8'
      -'10.0.0.0/8'
      -'172.16.0.0/12'
      -'192.168.0.0/16'
      -'169.254.0.0/16'
      -'::1/128'
      -'fe80::/10'
      -'fc00::/7'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high