ET MALWARE ELF/Facefish Client Response (202)

SID: 2033111Rev: 31 views
History
Sourceet/open
CreatedJune 7, 2021
UpdatedApril 17, 2023
Classificationtrojan-activity
alert tcp-pkt $HOME_NET any -> $EXTERNAL_NET 443 (msg:"ET MALWARE ELF/Facefish Client Response (202)"; flow:established,to_server; flowbits:set,ET.facefish; dsize:8; content:"|08 00 02 02|"; startswith; reference:url,blog.netlab.360.com/ssh_stealer_facefish_en; reference:md5,38fb322cc6d09a6ab85784ede56bc5a7; reference:md5,63dc3037bf0022e2d281f0463529bf60; classtype:trojan-activity; sid:2033111; rev:3; metadata:affected_product Mac_OSX, affected_product Linux, attack_target Client_Endpoint, created_at 2021_06_07, deployment Perimeter, malware_family ELF_Facefish, confidence High, signature_severity Major, tag RAT, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_04_17;)

References

urlblog.netlab.360.com/ssh_stealer_facefish_en
md5
38fb322cc6d09a6ab85784ede56bc5a7
md5
63dc3037bf0022e2d281f0463529bf60

Metadata

affected productLinux
attack targetClient_Endpoint
created at2021_06_07
deploymentPerimeter
malware familyELF_Facefish
confidenceHigh
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2023_04_17

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!