Network Communication Initiated To Portmap.IO Domain

 Original Source: [Sigma source]
Title: Network Communication Initiated To Portmap.IO Domain
Status: test
Description:Detects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
References:
  -https://portmap.io/
  -https://github.com/rapid7/metasploit-framework/issues/11337
  -https://pro.twitter.com/JaromirHorejsi/status/1795001037746761892/photo/2
Author: Florian Roth (Nextron Systems)
Date: 2024-05-31
modified:None
Tags:
  • -'attack.t1041'
  • -'attack.command-and-control'
  • -'attack.t1090.002'
  • -'attack.exfiltration'
Logsource:
  • category: network_connection
  • product: windows
Detection:
  selection:
    Initiated: 'true'
    DestinationHostname|endswith: '.portmap.io'
  condition:selection
Falsepositives:
  -Legitimate use of portmap.io domains
Level: medium