LOLBIN Connecting to a Rare Host

The
LOLBin Connecting to a Rare Host
alert indicates that a living-off-the-land binary is communicating with an external host or domain which is rarely accessed by hosts in your organization. This may indicate malicious intent.

Synopsis

10 minutes
3 days
14 days
10 minutes
Agent endpoint data
Severity
Medium

Description

A living-off-the-land binary (a benign system executable) connected to a host outside your organization, which very few other hosts connected to.

Attacker's Goals

Beacon to C2 server and/or exfiltrate data.

Investigative Actions

Check whether the process was injected to or otherwise subverted for malicious use.

Recommended For You