Skip to content

Hide Navigation Hide TOC

Outbound Network Connection Initiated By Microsoft Dialer (37e4024a-6c80-4d8f-b95d-2e7e94f3a8d1)

Detects outbound network connection initiated by Microsoft Dialer. The Microsoft Dialer, also known as Phone Dialer, is a built-in utility application included in various versions of the Microsoft Windows operating system. Its primary function is to provide users with a graphical interface for managing phone calls via a modem or a phone line connected to the computer. This is an outdated process in the current conext of it's usage and is a common target for info stealers for process injection, and is used to make C2 connections, common example is "Rhadamanthys"

Cluster A Galaxy A Cluster B Galaxy B Level
Outbound Network Connection Initiated By Microsoft Dialer (37e4024a-6c80-4d8f-b95d-2e7e94f3a8d1) Sigma-Rules Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern 1
Application Layer Protocol - T1071 (355be19c-ffc9-46d5-8d50-d6a036c675b6) Attack Pattern Web Protocols - T1071.001 (df8b2a25-8bdf-4856-953c-a04372b1c161) Attack Pattern 2