Back to Rule

Rule History

SID: 2022310 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 3Dec 24, 2015, 12:00 PM

ET MALWARE BBSRAT GET request CnC

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE BBSRAT GET request CnC"; flow:to_server,established; http.method; content:"GET"; http.uri; content:"/bbs/"; depth:5; fast_pattern; content:"/forum.php?sid="; distance:0; pcre:"/^\/bbs\/(?P<counter>[a-f0-9]+)\/forum\.php\?sid=(?P=counter)$/i"; http.user_agent; content:"Mozilla/4.0 (compatible|3b 20|Windows NT 5.1)"; startswith; http.cookie; pcre:"/[A-F0-9]{8}(?:-[A-F0-9]{4}){2}-[A-F0-9]{8}/"; reference:md5,8cd233d3f226cb1bf6bf15aca52e0e36; reference:url,researchcenter.paloaltonetworks.com/2015/12/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/; classtype:command-and-control; sid:2022310; rev:3; metadata:created_at 2015_12_24, signature_severity Major, updated_at 2020_06_16;)

Dec 24, 2015, 12:00 PM

Jun 16, 2020, 12:00 PM

Dec 24, 2015, 12:00 PM

Sep 10, 2024, 1:01 PM

rules/emerging-malware.rules