Windows 3CXDesktopApp.exe Beaconing to Suspicious 3CX-Related Domains (Netcon)

Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon

FreeReviewedSigma · High · v4
Product
windows
Category
network_connection
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-03-29
Updated
2026-07-31

What it detects

This rule flags network connections where 3CXDesktopApp.exe attempts to reach destination hostnames containing a set of domains associated with suspected 3CX Desktop App compromise activity. Beaconing-style traffic can indicate command-and-control or staging communication with an attacker-controlled infrastructure. It relies on network connection telemetry for process image name and the destination hostname observed in Windows network events.

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.