ET MALWARE Mylobot Receiving XOR Encrypted Config (0xde)
Sourceet/open
CreatedNovember 15, 2018
UpdatedJuly 26, 2019
Classificationtrojan-activity
alert tcp $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Mylobot Receiving XOR Encrypted Config (0xde)"; flow:established,from_server; content:"|00 00 00 00|"; depth:4; content:"|b6 aa aa ae e4 f1 f1|"; distance:1; within:7; fast_pattern; content:"|de 00 00 00 00|"; distance:0; reference:url,www.netformation.com/our-pov/mylobot-continues-global-infections/; classtype:trojan-activity; sid:2026613; rev:1; metadata:attack_target Client_Endpoint, created_at 2018_11_15, deployment Perimeter, malware_family Mylobot, performance_impact Low, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
Metadata
attack targetClient_Endpoint
created at2018_11_15
deploymentPerimeter
malware familyMylobot
performance impactLow
confidenceMedium
signature severityMajor
updated at2019_07_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!