TeamViewer Domain Query By Non-TeamViewer Application

 Original Source: [Sigma source]
Title: TeamViewer Domain Query By Non-TeamViewer Application
Status: test
Description:Detects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
References:
  -https://www.teamviewer.com/en-us/
Author: Florian Roth (Nextron Systems)
Date: 2022-01-30
modified:2023-09-18
Tags:
  • -'attack.command-and-control'
  • -'attack.t1219.002'
Logsource:
  • product: windows
  • category: dns_query
Detection:
  selection:
    QueryName:
      -'taf.teamviewer.com'
      -'udp.ping.teamviewer.com'

  filter_main_teamviewer:
    Image|contains: 'TeamViewer'
  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown binary names of TeamViewer
  -Depending on the environment the rule might require some initial tuning before usage to avoid FP with third party applications
Level: medium