Potential Pikabot C2 Activity — Detection Rule

Detects the execution of rundll32 that leads to an external network connection. The malware Pikabot has been seen to use this technique to initiate C2-communication through hard-coded Windows binaries.

Read the full analysis on IntelFusions