ET MALWARE Observed DNS Query to Stitch C2 Domain

SID: 2029766Rev: 20 views
History
Sourceet/open
CreatedMarch 31, 2020
UpdatedNovember 11, 2020
Classificationdomain-c2
alert dns $HOME_NET any -> any any (msg:"ET MALWARE Observed DNS Query to Stitch C2 Domain"; dns.query; content:"system0_update04driver_roots.dynamic-dns.net"; bsize:44; nocase; reference:url,securelist.com/holy-water-ongoing-targeted-water-holing-attack-in-asia/96311/; classtype:domain-c2; sid:2029766; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2020_03_31, deployment Perimeter, malware_family Stitch, confidence High, signature_severity Major, updated_at 2020_11_11;)

Metadata

affected productWindows_XP_Vista_7_8_10_Server_32_64_Bit
attack targetClient_Endpoint
created at2020_03_31
deploymentPerimeter
malware familyStitch
confidenceHigh
signature severityMajor
updated at2020_11_11

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!