ET MALWARE Backdoor.TurlaCarbon.A C2 HTTP Request

SID: 2020241Rev: 30 views
History
Sourceet/open
CreatedJanuary 22, 2015
UpdatedMay 14, 2020
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Backdoor.TurlaCarbon.A C2 HTTP Request"; flow:to_server,established; http.method; content:"POST"; http.uri; content:"?uid="; content:"&context="; distance:0; content:"&mode=text&"; fast_pattern; distance:0; content:"data="; pcre:"/\?uid=\d+&context=\w+&mode=text&data=\w+$/"; reference:url,blog.gdatasoftware.com/blog/article/analysis-of-project-cobra.html; classtype:command-and-control; sid:2020241; rev:3; metadata:created_at 2015_01_22, signature_severity Major, updated_at 2020_05_14;)

Metadata

created at2015_01_22
signature severityMajor
updated at2020_05_14

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!