2acebc90f2
fix: Dllhost.EXE Initiated Network Connection To Non-Local IP Address - Add additional filter fix: Outbound RDP Connections Over Non-Standard Tools - Update filters fix: Rundll32 Execution With Uncommon DLL Extension - Error in filter logic remove: Suspicious Non-Browser Network Communication With Reddit API update: BITS Transfer Job Download From File Sharing Domains - Add additional domains update: Dfsvc.EXE Initiated Network Connection Over Uncommon Port - Update image and list of ports update: HH.EXE Initiated HTTP Network Connection - Update list of ports update: Microsoft Binary Suspicious Communication Endpoint - Enhance list of paths and filters update: Msiexec.EXE Initiated Network Connection Over HTTP - Update destination ports update: Network Connection Initiated To Mega.nz - Update domains update: Office Application Initiated Network Connection Over Uncommon Ports - Update list of ports update: Office Application Initiated Network Connection To Non-Local IP - update list of filters update: Potential Dead Drop Resolvers - Update domains and filters update: Remote CHM File Download/Execution Via HH.EXE - Enhance logic update: Suspicious Download From File-Sharing Website Via Bitsadmin - Add additional domains update: Suspicious File Download From File Sharing Domain Via Curl.EXE - Add additional domains update: Suspicious File Download From File Sharing Websites - Add additional domains update: Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE - Add additional domains update: Suspicious Remote AppX Package Locations - Add additional domains update: Unusual File Download From File Sharing Websites - Add additional domains
31 lines
1.1 KiB
YAML
31 lines
1.1 KiB
YAML
title: Network Connection Initiated Via Notepad.EXE
|
|
id: e81528db-fc02-45e8-8e98-4e84aba1f10b
|
|
status: test
|
|
description: |
|
|
Detects a network connection that is initiated by the "notepad.exe" process.
|
|
This might be a sign of process injection from a beacon process or something similar.
|
|
Notepad rarely initiates a network communication except when printing documents for example.
|
|
references:
|
|
- https://web.archive.org/web/20200219102749/https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1492186586.pdf
|
|
- https://www.cobaltstrike.com/blog/why-is-notepad-exe-connecting-to-the-internet
|
|
author: EagleEye Team
|
|
date: 2020/05/14
|
|
modified: 2024/02/02
|
|
tags:
|
|
- attack.command_and_control
|
|
- attack.execution
|
|
- attack.defense_evasion
|
|
- attack.t1055
|
|
logsource:
|
|
category: network_connection
|
|
product: windows
|
|
detection:
|
|
selection:
|
|
Image|endswith: '\notepad.exe'
|
|
filter_optional_printing:
|
|
DestinationPort: 9100
|
|
condition: selection and not 1 of filter_optional_*
|
|
falsepositives:
|
|
- Printing documents via notepad might cause communication with the printer via port 9100 or similar.
|
|
level: high
|