Skip to content
Threat Feed

Tag

Network-Traffic

12 briefs RSS
low advisory

Unusual DNS Activity Detected by Machine Learning

An Elastic machine learning rule detects rare and unusual DNS queries that indicate potential malicious network activity, including initial access via phishing or malicious documents, persistence, command-and-control (C2) communication, or data exfiltration attempts by adversaries.

command-and-control exfiltration initial-access machine-learning network-traffic dns-anomaly elastic-security endpoint-detection
4t
low advisory

Unusual Web User Agent Detected via Machine Learning

Elastic's machine learning rule identifies rare and anomalous web user agents originating from local systems, indicating potential command-and-control, data exfiltration, or persistence activities by malware or specialized tools, enabling detection engineers to investigate unusual web browsing from non-browser processes.

Kibana +4 command-and-control network-traffic machine-learning elastic
1t
low advisory

Unusual Web Request Detection via Machine Learning

Elastic's machine learning job identifies rare and unusual URLs accessed through web browsing or network traffic, signaling potential initial access, persistence, command-and-control, or data exfiltration activities that deviate from normal user behavior or legitimate application traffic patterns.

machine-learning-detection network-traffic command-and-control initial-access
3t
low advisory

Potential DGA Activity Detected by Elastic Machine Learning

An Elastic machine learning rule detects potential Domain Generation Algorithm (DGA) activity, commonly used by malware for command and control (C2) communication, by analyzing DNS requests from source IP addresses to identify aggregate patterns indicative of DGA usage.

dga command-and-control machine-learning dns elastic network-traffic
2t
high threat

Halfbaked Malware Command and Control Beaconing Detected

FIN7 is leveraging Halfbaked malware to establish persistence and conduct command and control (C2) operations within compromised networks, using HTTP and TLS protocols with specific URL structures (e.g., `http://[IP_ADDRESS]/cd`) and common ports (53, 80, 8080, 443) for detection evasion and data exfiltration.

FIN7 +2 command-and-control malware halfbaked network-traffic
1r 2t 1i
high threat

Possible FIN7 DGA Command and Control Behavior

FIN7 threat group utilizes a specific Domain Generation Algorithm (DGA) for command and control (C2), characterized by domains with 4-5 alphabetic characters and specific top-level domains such as .pw, .us, .club, .info, .site, or .top, enabling persistence and continued operations within target networks.

FIN7 +2 command-and-control dga network-traffic persistence
1r 2t
high threat

Cobalt Strike Command and Control Beacon Detection

Adversaries, notably FIN7, deploy Cobalt Strike beacons on compromised systems to establish command and control (C2) channels, utilizing specific network activity algorithms and domain naming conventions for communication over protocols like HTTP or TLS, posing a critical risk of further compromise and data exfiltration.

Cobalt Strike FIN7 +2 command-and-control malware network-traffic cobalt-strike threat-detection
1r 2t
high advisory

RPC (Remote Procedure Call) Services Exposed to the Internet

Threat actors frequently exploit internet-exposed Remote Procedure Call (RPC) services, primarily on port TCP/135, as an initial access or backdoor vector, leading to unauthorized system access, internal network compromise, and potentially data exfiltration or ransomware deployment.

network-traffic initial-access lateral-movement vulnerability misconfiguration network
1r 3t
low advisory

Potential Data Exfiltration to Unusual Geographic Region via Machine Learning

A machine learning job has detected potential data exfiltration activity to an unusual geographical region, specifically by region name, indicating exfiltration over command and control channels.

data-exfiltration machine-learning network-traffic
2r 1t
high advisory

Detecting RPC Traffic to the Internet

This brief focuses on detecting Remote Procedure Call (RPC) traffic originating from internal networks and reaching the public internet, which is indicative of potential initial access or backdoor activity.

Elastic License v2 network-traffic initial-access lateral-movement rpc
2r 2t
low threat

Suspicious SMTP Activity on Port 26/TCP

This rule detects SMTP traffic on TCP port 26, an alternative to the standard port 25 that the BadPatch malware family has used for command and control of Windows systems.

BadPatch command-and-control exfiltration network-traffic
2r 3t
medium advisory

Large ICMP Traffic Detection

This analytic identifies excessive ICMP traffic to external IP addresses exceeding 1,000 bytes, potentially indicating command and control activity, data exfiltration, or covert communication channels.

Splunk Enterprise +4 network-traffic command-and-control data-exfiltration
2r 1t