Back to Rule

Rule History

SID: 2047715 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 1Aug 23, 2023, 12:00 PM

ET MALWARE Carderbee APT Related Activity

alert tcp $HOME_NET any -> $EXTERNAL_NET 443 (msg:"ET MALWARE Carderbee APT Related Activity"; flow:established,to_server; dsize:10; content:"hp_socket|00|"; fast_pattern; reference:md5,5a122e86a8f134e42ebae8510404df3d; reference:url,symantec-enterprise-blogs.security.com/blogs/threat-intelligence/carderbee-software-supply-chain-certificate-abuse; classtype:trojan-activity; sid:2047715; rev:1; metadata:attack_target Client_and_Server, created_at 2023_08_23, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_08_23; target:src_ip;)

Aug 23, 2023, 12:00 PM

Aug 23, 2023, 12:00 PM

Aug 23, 2023, 9:00 PM

Aug 19, 2025, 9:35 PM

rules/emerging-malware.rules