ET MALWARE Cobalt Strike CnC Beacon (GET)

7.0.35.0SID: 2071990Rev: 1Enabled6 views
Sourceet/open
Fileemerging-malware.rules
CreatedSeptember 10, 2026
UpdatedSeptember 10, 2026
Classificationtrojan-activity
alert http1 $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Cobalt Strike CnC Beacon (GET)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/api/v2/analytics|3f|"; fast_pattern; startswith; content:"id|3d|"; content:"timestamp|3d|"; http.header_names; content:"|0d 0a|Accept|0d 0a|Accept-Language|0d 0a|Accept-Encoding|0d 0a|"; startswith; content:"|0d 0a|Referer|0d 0a|"; content:"|0d 0a|Cookie|0d 0a|"; reference:md5,98e37601f3e18e16a0aa3fe7aca90dff; classtype:trojan-activity; sid:2071990; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Windows_11, attack_target Client_and_Server, tls_state TLSDecrypt, created_at 2026_09_10, deployment Perimeter, deployment SSLDecrypt, malware_family Cobalt_Strike, performance_impact Low, confidence High, signature_severity Major, updated_at 2026_09_10, mitre_tactic_id TA0037, mitre_tactic_name Command_And_Control, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel; target:src_ip;)

References

md5
98e37601f3e18e16a0aa3fe7aca90dff

Metadata

affected productWindows_11
attack targetClient_and_Server
tls stateTLSDecrypt
created at2026_09_10
deploymentSSLDecrypt
malware familyCobalt_Strike
performance impactLow
confidenceHigh
signature severityMajor
updated at2026_09_10
mitre tactic idTA0037
mitre tactic nameCommand_And_Control
mitre technique idT1041
mitre technique nameExfiltration_Over_C2_Channel

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!