This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potentially Suspicious Malware Callback Communication - Linux
Original Source:
[Sigma source]
Title:
Potentially Suspicious Malware Callback Communication - Linux
Status:
test
Description:
Detects programs that connect to known malware callback ports based on threat intelligence reports.
References:
-https://www.mandiant.com/resources/blog/triton-actor-ttp-profile-custom-attack-tools-detections
-https://www.mandiant.com/resources/blog/ukraine-and-sandworm-team
-https://www.elastic.co/guide/en/security/current/potential-non-standard-port-ssh-connection.html
-https://thehackernews.com/2024/01/systembc-malwares-c2-server-analysis.html
-https://www.cybereason.com/blog/sliver-c2-leveraged-by-many-threat-actors
Author:
hasselj
Date:
2024-05-10
modified:
None
Tags:
-'attack.persistence'
-'attack.command-and-control'
-'attack.t1571'
Logsource:
category: network_connection
product: linux
Detection:
selection:
Initiated
:
'true'
DestinationPort
:
-'888'
-'999'
-'2200'
-'2222'
-'4000'
-'4444'
-'6789'
-'8531'
-'50501'
-'51820'
filter_main_local_ranges:
DestinationIp|cidr
:
-'127.0.0.0/8'
-'10.0.0.0/8'
-'172.16.0.0/12'
-'192.168.0.0/16'
-'169.254.0.0/16'
-'::1/128'
-'fe80::/10'
-'fc00::/7'
condition
:
selection and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high