Rare access to known advertising domains
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Day
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent
ATT&CK Tactic
Command and Control (TA0011), Persistence (TA0003)
ATT&CK Technique
Application Layer Protocol (T1071), Software Extensions: Browser Extensions (T1176.001)
Severity
Informational
Description
The endpoint performed many connections to unpopular advertising domains. This could indicate the presence of adware on the endpoint.
Attacker's Goals
Causing the user to view excessive advertising content.
Investigative actions
Investigate the infected machine and search for suspicious browser extensions, see if changes were made to the homepage or if the browser is slower than usual, check whether sites that do not have ads usually, display ads when accessed from the possibly infected endpoint.
Search for suspicious redirections or proxy configuration on the infected machine.
Search for a C&C communication.
Variations
Was this helpful?
