ET MALWARE DDoS.XOR Checkin via HTTP

SID: 2021336Rev: 60 views
History
Sourceet/open
CreatedJune 24, 2015
UpdatedAugust 25, 2020
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE DDoS.XOR Checkin via HTTP"; flow:established,to_server; http.user_agent; content:"MSIE 6.0|3b 20|Windows NT 5.2|3b 20|SV1|3b 20|TencentTraveler|20 3b 20|.NET CLR 1.1.4322"; fast_pattern; reference:md5,d818d056bbf7e227151d40c8bd539976; reference:url,blog.checkpoint.com/wp-content/uploads/2015/10/sb-report-threat-intelligence-groundhog.pdf; classtype:command-and-control; sid:2021336; rev:6; metadata:affected_product Linux, attack_target Client_and_Server, created_at 2015_06_24, deployment Perimeter, malware_family DDoS_XOR, performance_impact Low, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_08_25;)

Metadata

affected productLinux
attack targetClient_and_Server
created at2015_06_24
deploymentPerimeter
malware familyDDoS_XOR
performance impactLow
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2020_08_25

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!