Versions (4)
Version DetailsCurrent
Rev: 5 • Nov 6, 2017, 12:00 PMET MALWARE RouteX CnC Domain (2fa3c2fa16c47d9b9bff8986a42b048f .com) in DNS Lookup
alert dns $HOME_NET any -> any any (msg:"ET MALWARE RouteX CnC Domain (2fa3c2fa16c47d9b9bff8986a42b048f .com) in DNS Lookup"; dns.query; content:"2fa3c2fa16c47d9b9bff8986a42b048f.com"; fast_pattern; nocase; bsize:36; reference:url,forkbomb.us/press-releases/2017/09/08/routex-press-release.html; classtype:command-and-control; sid:2024964; rev:5; metadata:affected_product Linux, attack_target Networking_Equipment, created_at 2017_11_06, deployment Internal, performance_impact Moderate, confidence High, signature_severity Major, updated_at 2022_07_22;)
Nov 6, 2017, 12:00 PM
Jul 22, 2022, 12:00 PM
Sep 21, 2024, 3:00 AM
May 30, 2025, 12:04 AM
rules/emerging-malware.rules