Versions (2)
Version DetailsCurrent
Rev: 1 • Oct 8, 2025, 12:00 PMET HUNTING Request To Image Hosted on Archive .org With Minimal Request Headers
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING Request To Image Hosted on Archive .org With Minimal Request Headers"; flow:established,to_server; http.uri; pcre:"/\x2e(?:png|jpg|jpeg|svg|gif|tiff)$/i"; http.header_names; content:!"|0d 0a|user-agent|0d 0a|"; nocase; content:!"|0d 0a|referer|0d 0a|"; nocase; http.host; content:"archive.org"; endswith; fast_pattern; reference:url,x.com/jane_0sint/status/1975465601045770444; classtype:trojan-activity; sid:2065097; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Mac_OSX, affected_product Linux, attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2025_10_08, deployment Perimeter, deployment SSLDecrypt, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_10_08, mitre_tactic_id TA0011, mitre_tactic_name Command_And_Control, mitre_technique_id T1105, mitre_technique_name Ingress_Tool_Transfer; target:src_ip;)
Oct 8, 2025, 12:00 PM
Oct 8, 2025, 12:00 PM
Oct 8, 2025, 9:38 PM
Oct 9, 2025, 9:35 PM
rules/emerging-hunting.rules