Analytics BIOC Informational

Suspicious process accessed a site masquerading as Google

A suspicious process accessed a site masquerading as Google.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Command and Control (TA0011) Defense Evasion (TA0005)
ATT&CK techniques: Web Service: Bidirectional Communication (T1102.002) Masquerading (T1036)
Attacker's goals:

Masquerade legitimate looking Google services for defense evasion and C&C.

Investigative actions:

See whether this site has a malicious reputation. Follow process activities. Monitor traffic to the site.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Suspicious process resolved the DNS name of a site masquerading as Google Informational