Back to Rule

Rule History

SID: 3301153 • Source: pawpatrules

Versions (2)

Version DetailsCurrent

Rev: 3Mar 3, 2024, 6:45 AM

🐾 - 🚨 👀 geoplugin.net JSON lookup public IP address from local network - Used by Remcos RAT - Possible Leak 🚱

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"🐾 - 🚨 👀 geoplugin.net JSON lookup public IP address from local network - Used by Remcos RAT - Possible Leak 🚱"; flow:to_server, stateless; threshold: type limit, track by_src,count 1, seconds 3600; http.host.raw; content:"geoplugin.net"; fast_pattern; nocase; http.method; content:"GET"; http.uri; content:"/json.gp"; reference:url,https://blog.talosintelligence.com/threat-roundup-1021-1028-2/; metadata:created_at 2024_03_03, updated_at 2024_08_08; sid:3301153; rev:3; classtype:external-ip-check;)

Mar 3, 2024, 6:45 AM

Aug 8, 2024, 12:00 PM

Mar 3, 2024, 6:45 AM

May 29, 2025, 11:12 PM

rules/PAW-PATRULES_LEAKS.rules