ET MALWARE Sednit Connectivity Check 0 Byte POST
Sourceet/open
CreatedJuly 22, 2015
UpdatedApril 29, 2024
Classificationtargeted-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Sednit Connectivity Check 0 Byte POST"; flow:to_server,established; http.method; content:"POST"; http.uri; content:!"=http"; content:"/?"; pcre:"/\.[a-z]{3,4}\/\?[A-Za-z0-9]+=(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})$/"; http.header; content:"Content-Length|3a 20|0|0D 0A|"; fast_pattern; http.host; content:"google."; within:10; pcre:"/^(?:www\.)?google(?:\.[a-z]{2,3})+$/"; http.header_names; content:!"Referer|0d 0a|"; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used; classtype:targeted-activity; sid:2021506; rev:7; metadata:created_at 2015_07_22, performance_impact Significant, signature_severity Major, updated_at 2024_04_29;)
References
Metadata
created at2015_07_22
performance impactSignificant
signature severityMajor
updated at2024_04_29
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!