ET ATTACK_RESPONSE 401TRG Perl DDoS IRCBot File Download
Sourceet/open
CreatedNovember 7, 2017
UpdatedJuly 26, 2019
Classificationtrojan-activity
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET ATTACK_RESPONSE 401TRG Perl DDoS IRCBot File Download"; flow:established,from_server; content:"|6d 79 20 24 70 72 6f 63 65 73 73 20 3d 20 24 72 70 73 5b 72 61 6e 64 20 73 63 61 6c 61 72 20 40 72 70 73 5d 3b|"; classtype:trojan-activity; sid:2024977; rev:2; metadata:affected_product Apache_HTTP_server, attack_target Web_Server, created_at 2017_11_07, deployment Datacenter, malware_family webshell, performance_impact Moderate, confidence High, signature_severity Major, updated_at 2019_07_26;)
Metadata
affected productApache_HTTP_server
attack targetWeb_Server
created at2017_11_07
deploymentDatacenter
malware familywebshell
performance impactModerate
confidenceHigh
signature severityMajor
updated at2019_07_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!