ET MALWARE W32/Fsysna.Downloader CnC Beacon

SID: 2018462Rev: 70 views
History
Sourceet/open
CreatedMay 9, 2014
UpdatedMarch 6, 2024
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Fsysna.Downloader CnC Beacon"; flow:established,to_server; http.method; content:"GET"; http.uri; content:".php"; http.header; content:"Content-Type|3a 20|*/*|0d 0a|"; depth:19; http.user_agent; content:"Mozilla/4.0 (compatible|3B 20|MSIE "; content:".0|3B 20|Win32|29 3B 20|"; distance:1; within:15; fast_pattern; pcre:"/^\d+$/R"; reference:url,blogs.mcafee.com/mcafee-labs/targeted-attacks-japanese-firm-use-old-activex-vulnerability; reference:md5,2b91011e122364148698a249c2f4b7fe; reference:md5,6c040be9d91083ffba59405f9b2c89bf; classtype:command-and-control; sid:2018462; rev:7; metadata:attack_target Client_Endpoint, created_at 2014_05_09, deployment Perimeter, deprecation_reason Relevance, signature_severity Major, tag c2, updated_at 2024_03_06, reviewed_at 2024_03_06, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel;)

Metadata

attack targetClient_Endpoint
created at2014_05_09
deploymentPerimeter
deprecation reasonRelevance
signature severityMajor
tagc2
updated at2024_03_06
reviewed at2024_03_06
mitre tactic idTA0010
mitre tactic nameExfiltration
mitre technique idT1041
mitre technique nameExfiltration_Over_C2_Channel

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!