Back to Rule

Rule History

SID: 2024977 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 2Nov 7, 2017, 12:00 PM

ET ATTACK_RESPONSE 401TRG Perl DDoS IRCBot File Download

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET ATTACK_RESPONSE 401TRG Perl DDoS IRCBot File Download"; flow:established,from_server; content:"|6d 79 20 24 70 72 6f 63 65 73 73 20 3d 20 24 72 70 73 5b 72 61 6e 64 20 73 63 61 6c 61 72 20 40 72 70 73 5d 3b|"; classtype:trojan-activity; sid:2024977; rev:2; metadata:affected_product Apache_HTTP_server, attack_target Web_Server, created_at 2017_11_07, deployment Datacenter, malware_family webshell, performance_impact Moderate, confidence High, signature_severity Major, updated_at 2019_07_26;)

Nov 7, 2017, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-attack_response.rules