Back to Rule

Rule History

SID: 2018620 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 7Jul 1, 2014, 12:00 PM

ET MALWARE Downloader.Win32.Tesch.A Bot Command Checkin 2

alert tcp-pkt $HOME_NET any -> $EXTERNAL_NET 443 (msg:"ET MALWARE Downloader.Win32.Tesch.A Bot Command Checkin 2"; flow:established,to_server; dsize:51; content:"|01 00 30 01 01 00|"; fast_pattern; startswith; flowbits:set,ET.Tesch; reference:md5,872763d48730506af7eee0bf22c2f47b; classtype:command-and-control; sid:2018620; rev:7; metadata:created_at 2014_07_01, deprecation_reason Relevance, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_07, reviewed_at 2024_03_07;)

Jul 1, 2014, 12:00 PM

Mar 7, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

Jan 19, 2026, 10:35 PM

rules/emerging-malware.rules