ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
28 lines
1.1 KiB
YAML
28 lines
1.1 KiB
YAML
title: ARTEX Self-Update Egress User-Agent
|
|
id: e96380a3-2a34-4237-be2b-088ad9cc947d
|
|
status: experimental
|
|
description: |
|
|
Detects outbound (egress) HTTP requests whose User-Agent is "artex-selfupdate", used by the
|
|
ARTEX self-update routine when it queries code-repository hosts (for example GitHub releases)
|
|
for a newer binary. Seeing this User-Agent leave an internal host toward a code-hosting
|
|
service suggests an ARTEX binary is installed on that host. This is primarily an operator and
|
|
forensic indicator on a (possibly compromised relay) host, not a target-side signal.
|
|
references:
|
|
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-ko.md
|
|
- https://github.com/jiwoochris/artex-ko/blob/main/docs/defense-en.md
|
|
- https://github.com/jiwoochris/artex-ko
|
|
author: artex-ko defense guide
|
|
date: 2026-10-05
|
|
tags:
|
|
- attack.command-and-control
|
|
- attack.t1105
|
|
logsource:
|
|
category: proxy
|
|
detection:
|
|
selection:
|
|
c-useragent: 'artex-selfupdate'
|
|
condition: selection
|
|
falsepositives:
|
|
- Unlikely; this User-Agent string is specific to the ARTEX self-update client.
|
|
level: medium
|