Detection-focused writeup on a SpiceRAT C2 cluster connected to Bitdefender's SilkParasite report. Everything here is reproducible from scan data.
Hunting hooks: a reused decoy page collapses to one SHA-256 body hash across 13 hosts; a TLC-issued cert (subject azure.uzrailwaystax[.]com, SHA-256 in the post) sits on 8 hosts; hardened RDP on unusual high ports (64350, 64330, 65535, 65111) shows up under a tls fingerprint rather than RDP, so filter for that. Two nginx versions (1.29.3 and 1.31.3) recur across the fleet.
Full IOC tables (IPs, domains, cert fields, subdomain and passive DNS history) plus the HuntSQL queries are in the post, ready for retro hunts.
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
https://hunt.io/blog/silkparasite-spicerat-central-asia-infrastructure
Source: r/blueteamsec · by /u/Straight-Practice-99