Versions (2)
Version DetailsCurrent
Rev: 3 • Mar 3, 2024, 6:45 AM🐾 - 🚨 👀 geoplugin.net JSON lookup public IP address from local network - Used by Remcos RAT - Possible Leak 🚱
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"🐾 - 🚨 👀 geoplugin.net JSON lookup public IP address from local network - Used by Remcos RAT - Possible Leak 🚱"; flow:to_server, stateless; threshold: type limit, track by_src,count 1, seconds 3600; http.host.raw; content:"geoplugin.net"; fast_pattern; nocase; http.method; content:"GET"; http.uri; content:"/json.gp"; reference:url,https://blog.talosintelligence.com/threat-roundup-1021-1028-2/; metadata:created_at 2024_03_03, updated_at 2024_08_08; sid:3301153; rev:3; classtype:external-ip-check;)
Mar 3, 2024, 6:45 AM
Aug 8, 2024, 12:00 PM
Mar 3, 2024, 6:45 AM
May 29, 2025, 11:12 PM
rules/PAW-PATRULES_LEAKS.rules