ET MALWARE Possible Dyre SSL Cert Aug 31 2015
Sourceet/open
CreatedAugust 31, 2015
UpdatedApril 4, 2024
Classificationtrojan-activity
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Possible Dyre SSL Cert Aug 31 2015"; flow:established,to_client; tls.certs; content:"|06 03 55 04 06 13 02|"; distance:0; pcre:"/^[A-Z]{2}[01]/R"; content:"|55 04 08|"; distance:0; byte_test:1,>,9,1,relative; byte_test:1,<,121,1,relative; pcre:"/^.{2}[A-Z]{10,120}/R"; content:"|55 04 07|"; distance:0; content:"|55 04 0a|"; distance:0; content:"|55 04 03|"; byte_extract:1,1,cnlength,relative; content:!"|2e|"; within:cnlength; content:"|55 04 0b|"; distance:0; content:"|2a 86 48 86 f7 0d 01 09 01|"; fast_pattern; distance:0; pcre:"/^.{2}[a-z]+@[a-z]+\.com[01]/R"; reference:md5,26e83fa8b2f3eccfe975cd451933ae63; reference:url,us-cert.gov/ncas/alerts/TA14-300A; classtype:trojan-activity; sid:2021736; rev:5; metadata:attack_target Client_Endpoint, created_at 2015_08_31, deployment Perimeter, confidence Medium, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2024_04_04;)
References
| md5 | 26e83fa8b2f3eccfe975cd451933ae63 |
| url | us-cert.gov/ncas/alerts/TA14-300A |
Metadata
attack targetClient_Endpoint
created at2015_08_31
deploymentPerimeter
confidenceMedium
signature severityMajor
tagSSL_Malicious_Cert
updated at2024_04_04
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!