AN0158
Analytic 0158
Windows
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
WinEventLog:Sysmon
EventCode=3, 22
etw:Microsoft-Windows-NDIS-PacketCapture
TLS Handshake/Network Flow
[TargetDomain]
FQDN or IP for the hosting site of the dead drop (e.g., pastebin.com, twitter.com)
[TimeWindow]
Defines how close in time the suspicious network and process behavior must occur
[UserContext]
Filter by user or system accounts to reduce noise
AN0159
Analytic 0159
Linux
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
auditd:SYSCALL
connect
NSM:Flow
HTTP/TLS Logs
[TargetDomain]
Dead drop hosting domain (e.g., GitHub, Google Docs)
[PayloadEntropyThreshold]
Detects high entropy in payloads signaling obfuscation
[TimeWindow]
Causal proximity between access to resolver and follow-up connections
AN0160
Analytic 0160
macOS
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
macos:unifiedlog
subsystem: com.apple.network
macos:osquery
process_events/socket_events
[TargetService]
Known services abused for D2 (e.g., iCloud, Dropbox)
[UserContext]
Useful to isolate rare users accessing web services for C2
[TimeWindow]
Max time gap between dead drop resolver fetch and follow-on traffic
AN0161
Analytic 0161
ESXi
Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).
esxi:vobd
Network Events
NSM:Firewall
Outbound Connections
[DestinationIP]
Identifies unusual IP destinations embedded in traffic
[Protocol]
Used to detect uncommon protocols (e.g., DNS over HTTPS)
[TimeWindow]
Used to correlate outbound web requests with process execution