Back to Rule

Rule History

SID: 2064006 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 1Aug 13, 2025, 12:00 PM

ET MALWARE CastleLoader Payload Request (GET)

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE CastleLoader Payload Request (GET)"; flow:established,to_server; urilen:30; http.method; content:"GET"; http.uri; content:"/service/download/pymodule.bin"; fast_pattern; reference:md5,835ab1cf597812b0e6464c2e8f100678; classtype:trojan-activity; sid:2064006; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, tls_state plaintext, created_at 2025_08_13, deployment Perimeter, malware_family CastleLoader, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_08_13, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1189, mitre_technique_name Drive_by_Compromise; target:src_ip;)

Aug 13, 2025, 12:00 PM

Aug 13, 2025, 12:00 PM

Aug 13, 2025, 9:35 PM

Aug 14, 2025, 9:34 PM

rules/emerging-malware.rules