ET RETIRED Metasploit Meterpreter Reverse HTTPS certificate

SID: 2021178Rev: 82 views
History
Sourceet/open
CreatedJune 3, 2015
UpdatedJuly 14, 2025
Classificationtrojan-activity
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET RETIRED Metasploit Meterpreter Reverse HTTPS certificate"; flow:established,to_client; content:"|A3 0D 30 0B 30 09 06 03 55 1D 13 04 02 30 00|"; fast_pattern; content:"|16 03 03|"; pcre:"/^..\x0B.{9}\x30\x82..\x30\x82..\xA0\x03\x02\x01\x02\x02(?:\x09.{9}|\x08.{8})/Rs"; content:"|30 0D 06 09 2A 86 48 86 F7 0D 01 01 0B 05 00 30|"; within:16; pcre:"/^.\x31.\x30.\x06\x03\x55\x04\x03\x0C.([a-z]{2,9})\x30.\x17\x0D[0-9]{12}Z\x17\x0D[0-9]{12}Z\x30.\x31.\x30.\x06\x03\x55\x04\x03\x0C.\g{1}\x30\x82../Rs"; content:"|30 0D 06 09 2A 86 48 86 F7 0D 01 01 01 05 00 03 82|"; within:17; pcre:"/^...\x30\x82..\x02\x82...{256,257}/Rs"; content:"|02 03 01 00 01 A3 0D 30 0B 30 09 06 03 55 1D 13 04 02 30 00 30 0D 06 09 2A 86 48 86 F7 0D 01 01 0B 05 00|"; within:36; content:!"|06|ubuntu"; content:!"|04|mint"; content:!"|a9 d5 73 d2 a0 a5 a1 69|"; content:!"U|04 03 0c 09|localhost"; reference:url,blog.didierstevens.com/2015/05/11/detecting-network-traffic-from-metasploits-meterpreter-reverse-http-module; classtype:trojan-activity; sid:2021178; rev:8; metadata:affected_product Any, attack_target Client_and_Server, created_at 2015_06_03, deployment Perimeter, deployment Internet, deployment Internal, deployment Datacenter, former_category ATTACK_RESPONSE, confidence Low, signature_severity Critical, tag Metasploit, updated_at 2025_07_14;)

Metadata

affected productAny
attack targetClient_and_Server
created at2015_06_03
deploymentDatacenter
former categoryATTACK_RESPONSE
confidenceLow
signature severityCritical
tagMetasploit
updated at2025_07_14

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!