BIOC Informational

Ping to a known external IP address

Pinging a known external IP address is often used by malware to check internet connectivity.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Virtualization/Sandbox Evasion (T1497)
Indicator:

Process action type = execution AND target process name = ping.exe , ping AND target process cmd = *8.8.8.8* , *8.8.4.4* , *9.9.9.9* , *149.112.112.112* , *208.67.222.222* , *208.67.220.220* , *1.1.1.1* , *1.0.0.1* , *185.228.168.9* , *185.228.169.9* , *64.6.64.6* , *64.6.65.6* , *198.101.242.72* , *23.253.163.53* , *176.103.130.130* , *176.103.130.131* Process cgo name != cmd.exe AND thorium.exe AND 4nt.exe AND cgo signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash AND cgo signer != BeyondTrust Software Inc AND HP Inc. Host host os = windows

Preventable: yes