Detection rules › Sigma

Outbound Network Connection Initiated By Microsoft Dialer

Severity
high
Author
CertainlyP
Source
upstream

Detects outbound network connection initiated by Microsoft Dialer. The Microsoft Dialer, also known as Phone Dialer, is a built-in utility application included in various versions of the Microsoft Windows operating system. Its primary function is to provide users with a graphical interface for managing phone calls via a modem or a phone line connected to the computer. This is an outdated process in the current conext of it's usage and is a common target for info stealers for process injection, and is used to make C2 connections, common example is "Rhadamanthys"

MITRE ATT&CK coverage

TacticTechniques
Command & ControlT1071.001 Application Layer Protocol: Web Protocols

Event coverage

ProviderEvent IDTitle
Sysmon3Network connection

Stages and Predicates

Stage 1: selection

Image|endswith: ':\Windows\System32\dialer.exe'
Initiated: true

Stage 2: not 1 of filter_main_local_ranges

or:
DestinationIp|cidr: '10.0.0.0/8'
DestinationIp|cidr: '127.0.0.0/8'
DestinationIp|cidr: '169.254.0.0/16'
DestinationIp|cidr: '172.16.0.0/12'
DestinationIp|cidr: '192.168.0.0/16'
DestinationIp|cidr: '::1/128'
DestinationIp|cidr: 'fc00::/7'
DestinationIp|cidr: 'fe80::/10'

Indicators

Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.

FieldKindValues
DestinationIpcidr_match
  • 10.0.0.0/8 corpus 12 (sigma 12)
  • 127.0.0.0/8 corpus 13 (sigma 13)
  • 169.254.0.0/16 corpus 12 (sigma 12)
  • 172.16.0.0/12 corpus 12 (sigma 12)
  • 192.168.0.0/16 corpus 12 (sigma 12)
  • ::1/128 corpus 13 (sigma 13)
  • fc00::/7 corpus 12 (sigma 12)
  • fe80::/10 corpus 12 (sigma 12)
Imageends_with
  • :\Windows\System32\dialer.exe
Initiatedeq
  • true corpus 40 (sigma 40)