ET MALWARE Downloader.Win32.Tesch.A Server CnC Sending Executable

SID: 2018479Rev: 40 views
History
Sourceet/open
CreatedMay 15, 2014
UpdatedMarch 6, 2024
Classificationcommand-and-control
alert tcp $EXTERNAL_NET 443 -> $HOME_NET any (msg:"ET MALWARE Downloader.Win32.Tesch.A Server CnC Sending Executable"; flow:established,to_client; content:"This Program must be"; fast_pattern; content:"|0B 00|"; startswith; content:"|00|MZ"; distance:14; within:3; byte_jump:4,58,relative,little; content:"PE|00 00|"; distance:-64; within:4; reference:md5,28173e257188ce3b3cc663be661bc2c4; reference:md5,2bebb36872b4829f553326e102d014ed; classtype:command-and-control; sid:2018479; rev:4; metadata:created_at 2014_05_15, deprecation_reason Relevance, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_06, reviewed_at 2024_03_06;)

References

md5
28173e257188ce3b3cc663be661bc2c4
md5
2bebb36872b4829f553326e102d014ed

Metadata

created at2014_05_15
deprecation reasonRelevance
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2024_03_06
reviewed at2024_03_06

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!