ET EXPLOIT Actiontec C1000A backdoor account M1
Sourceet/open
CreatedNovember 28, 2017
UpdatedJanuary 3, 2025
Classificationattempted-admin
alert tcp any any -> $HOME_NET [23,2323] (msg:"ET EXPLOIT Actiontec C1000A backdoor account M1"; flow:established,to_server; content:"QwestM0dem"; fast_pattern; classtype:attempted-admin; sid:2025080; rev:3; metadata:affected_product Linux, attack_target IoT, created_at 2017_11_28, deployment Perimeter, malware_family Mirai, performance_impact Low, signature_severity Major, updated_at 2025_01_03;)
Metadata
affected productLinux
attack targetIoT
created at2017_11_28
deploymentPerimeter
malware familyMirai
performance impactLow
signature severityMajor
updated at2025_01_03
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!