Versions (4)
Version DetailsCurrent
Rev: 2 • Jun 13, 2022, 12:00 PMET MALWARE Aoqin Dragon APT Related Activity (GET)
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Aoqin Dragon APT Related Activity (GET)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:!"."; content:!"?"; content:!"&"; pcre:"/\/(?:[a-zA-Z0-9+/\x20]{4})*(?:[a-zA-Z0-9+/\x20]{2}==|[a-zA-Z0-9+/\x20]{5}=|[a-zA-Z0-9+/\x20]{4})(?:[a-zA-Z=]{4}?)$/"; http.header; content:!"Content-"; http.user_agent; content:"Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.66 Safari/537.36"; fast_pattern; bsize:101; http.header_names; content:!"Accept"; content:!"Referer|0d 0a|"; reference:md5,54510ab05e1aac891a234624459103a9; classtype:trojan-activity; sid:2036973; rev:2; metadata:attack_target Client_Endpoint, created_at 2022_06_13, deployment Perimeter, deprecation_reason Duplicate, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_06_14;)Jun 13, 2022, 12:00 PM
Jun 14, 2022, 12:00 PM
Sep 21, 2024, 3:00 AM
Sep 2, 2025, 9:35 PM
rules/emerging-malware.rules