ET MALWARE Possible Linux.Mirai DaHua Default Credentials Login

SID: 2023674Rev: 10 views
History
Sourceet/open
CreatedDecember 20, 2016
UpdatedJuly 26, 2019
Classificationattempted-admin
alert tcp $EXTERNAL_NET any -> $HOME_NET [6789] (msg:"ET MALWARE Possible Linux.Mirai DaHua Default Credentials Login"; flow:to_server,established; content:"888888|0d 0a|888888"; depth:14; content:"busybox telnetd -p"; distance:0; reference:url,isc.sans.edu/diary/21833; classtype:attempted-admin; sid:2023674; rev:1; metadata:attack_target IoT, created_at 2016_12_20, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2019_07_26;)

Metadata

attack targetIoT
created at2016_12_20
deploymentPerimeter
performance impactLow
confidenceMedium
signature severityMajor
updated at2019_07_26

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!