Firewall Alerts for C2 IP Traffic to 69.42.98.86 and 89.185.234.145

Alerts when firewall traffic involves the two specified IPs associated with presumed C2 communication.

FreeReviewedSigma · High · v5
Category
firewall
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-04-15
Updated
2026-07-31

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule flags firewall events where either source or destination IP matches 69.42.98.86 or 89.185.234.145, which are listed as C2 endpoints in the provided operational notes. Monitoring this traffic matters because direct network connections to known C2 infrastructure can indicate command-and-control activity. It relies on firewall telemetry that records source and destination IP addresses for inbound or outbound sessions.

Related detections9 linkedT1041 — drag to rearrange
Suspicious DNS Exfiltration to azurestaticprovider Backdoor Domain
Suspicious UAT-10608 Credential Harvesting C2 Beacon via HTTP
Malicious Vice Society Directory Crawling Script for Data Exfiltration - Via Ps_script (via ps_script)
Malicious PowerShell Exfiltration to webhook.site Following WSUS Exploitation
Suspicious InvisibleFerret C2 Endpoints over Port 1224 (via proxy)
Suspicious CurKeep Backdoor C2 API Endpoints (via proxy)
Suspicious DEEPPOST Data Exfiltration URI Pattern via BrazenBamboo
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Suspicious COOKIE SPIDER macOS Data Exfiltration via curl Archive Upload (via process_creation)
Firewall Alerts for C2 IP Traffic to 69.42.98.86 and 89.185.234.145
Pivot detection · T1041 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.