Removed rule. This rule is known, but it is no longer present in its source. Showing the last known version.Removed: Jul 5, 2026, 4:07 AM
THL Cobalt Strike Malleable C2 BOIE9 IE9 User-Agent Detected
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"THL Cobalt Strike Malleable C2 BOIE9 IE9 User-Agent Detected"; flow:established,to_server ; http.user_agent; content:"BOIE9|3B|ENUSSEM)"; endswith; nocase; sid:1900037; rev:1; metadata:affected_product Windows, attack_target Client_Endpoint, created_at 2026_04_08, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2026_04_08;)
Metadata
affected productWindows
attack targetClient_Endpoint
created at2026_04_08
deploymentPerimeter
performance impactLow
signature severityMajor
updated at2026_04_08
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!