Back to Rule

Rule History

SID: 2026579 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 1Nov 5, 2018, 12:00 PM

ET MALWARE Perl/Shellbot.SM IRC CnC Checkin

alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Perl/Shellbot.SM IRC CnC Checkin"; flow:established,to_server; content:"JOIN"; depth:4; content:"Procesor - model name"; distance:0; content:"Numar Procesoare"; distance:0; fast_pattern; content:"|3a|uid="; distance:0; content:"gid="; distance:0; content:"groups="; distance:0; reference:md5,ca42fda581175fd85ba7dab8243204e4; classtype:command-and-control; sid:2026579; rev:1; metadata:attack_target Client_and_Server, created_at 2018_11_05, deployment Perimeter, malware_family Shellbot_SM, performance_impact Low, confidence High, signature_severity Major, tag Perl, updated_at 2019_07_26;)

Nov 5, 2018, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-malware.rules