ET MALWARE Perl/Shellbot.SM IRC CnC Checkin
Sourceet/open
CreatedNovember 5, 2018
UpdatedJuly 26, 2019
Classificationcommand-and-control
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Perl/Shellbot.SM IRC CnC Checkin"; flow:established,to_server; content:"JOIN"; depth:4; content:"Procesor - model name"; distance:0; content:"Numar Procesoare"; distance:0; fast_pattern; content:"|3a|uid="; distance:0; content:"gid="; distance:0; content:"groups="; distance:0; reference:md5,ca42fda581175fd85ba7dab8243204e4; classtype:command-and-control; sid:2026579; rev:1; metadata:attack_target Client_and_Server, created_at 2018_11_05, deployment Perimeter, malware_family Shellbot_SM, performance_impact Low, confidence High, signature_severity Major, tag Perl, updated_at 2019_07_26;)
References
| md5 | ca42fda581175fd85ba7dab8243204e4 |
Metadata
attack targetClient_and_Server
created at2018_11_05
deploymentPerimeter
malware familyShellbot_SM
performance impactLow
confidenceHigh
signature severityMajor
tagPerl
updated at2019_07_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!