<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Brave Software — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/brave-software/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 04 Jan 2024 12:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/brave-software/feed.xml" rel="self" type="application/rss+xml"/><item><title>Detection of Command and Control Activity via Commonly Abused Web Services</title><link>https://feed.craftedsignal.io/briefs/2024-01-04-c2-web-services/</link><pubDate>Thu, 04 Jan 2024 12:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2024-01-04-c2-web-services/</guid><description>This rule detects command and control activity using common web services by identifying Windows hosts making DNS requests to a list of commonly abused web services from processes outside of known program locations, potentially indicating adversaries attempting to blend malicious traffic with legitimate network activity.</description><content:encoded><![CDATA[<p>Adversaries may implement command and control (C2) communications that use common web services to hide their activity. This attack technique is typically targeted at an organization and uses web services common to the victim network, which allows the adversary to blend into legitimate traffic activity. These popular services are typically targeted since they have most likely been used before compromise, which helps malicious traffic blend in. This detection focuses on identifying connections from Windows hosts to a predefined list of commonly abused web services from processes running outside of typical program installation directories, indicating a potential C2 channel leveraging legitimate services. The rule aims to detect this behavior by monitoring network connections and DNS requests originating from unusual locations.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial access is achieved via an unknown method (e.g., phishing, exploit).</li>
<li>Malware is installed on the victim&rsquo;s system, likely outside typical program directories.</li>
<li>The malware establishes a DNS connection to a commonly abused web service (e.g., pastebin.com, raw.githubusercontent.com) to obscure C2 traffic.</li>
<li>The malware sends encrypted or encoded commands to the web service.</li>
<li>The web service acts as an intermediary, relaying the commands to the attacker&rsquo;s C2 server.</li>
<li>The C2 server responds with instructions, which are then relayed back to the compromised host through the same web service.</li>
<li>The malware executes the received commands, potentially leading to data exfiltration, lateral movement, or other malicious activities.</li>
<li>The attacker maintains persistent access and control over the compromised system using the web service as a hidden C2 channel.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation can lead to data theft, system compromise, and further propagation within the network. Since commonly used web services are utilized, the malicious activity can blend in with legitimate network traffic, making it difficult to detect. The impact can range from minor data breaches to complete network compromise, depending on the attacker&rsquo;s objectives and the level of access gained.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the Sigma rule <code>Detect Commonly Abused Web Services via DNS</code> to your SIEM to identify suspicious DNS queries to known C2 web services originating from anomalous processes.</li>
<li>Enable DNS query logging on Windows endpoints to provide the data source required for the Sigma rule.</li>
<li>Review network connection logs for processes outside standard installation directories communicating with domains listed in the <code>query</code> section of the Sigma rule to identify potential C2 activity.</li>
<li>Implement network segmentation to limit the potential impact of compromised hosts.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>command-and-control</category><category>windows</category><category>threat-detection</category></item></channel></rss>