ET MALWARE BBSRAT GET request CnC

SID: 2022310Rev: 30 views
History
Sourceet/open
CreatedDecember 24, 2015
UpdatedJune 16, 2020
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE BBSRAT GET request CnC"; flow:to_server,established; http.method; content:"GET"; http.uri; content:"/bbs/"; depth:5; fast_pattern; content:"/forum.php?sid="; distance:0; pcre:"/^\/bbs\/(?P<counter>[a-f0-9]+)\/forum\.php\?sid=(?P=counter)$/i"; http.user_agent; content:"Mozilla/4.0 (compatible|3b 20|Windows NT 5.1)"; startswith; http.cookie; pcre:"/[A-F0-9]{8}(?:-[A-F0-9]{4}){2}-[A-F0-9]{8}/"; reference:md5,8cd233d3f226cb1bf6bf15aca52e0e36; reference:url,researchcenter.paloaltonetworks.com/2015/12/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/; classtype:command-and-control; sid:2022310; rev:3; metadata:created_at 2015_12_24, signature_severity Major, updated_at 2020_06_16;)

Metadata

created at2015_12_24
signature severityMajor
updated at2020_06_16

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!