ET MALWARE Gasket Submitting Logs to CnC

SID: 2033341Rev: 11 views
History
Sourceet/open
CreatedJuly 15, 2021
UpdatedJuly 15, 2021
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Gasket Submitting Logs to CnC"; flow:established,to_server; pcre:"/^[\x20-\x7e\r\n]{0,13}[^\x20-\x7e\r\n]/Psi"; http.method; content:"POST"; http.uri; content:"/cert/dist"; bsize:10; fast_pattern; http.user_agent; content:"Go-http-client"; startswith; http.host; pcre:"/^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}(?:\:\d{1,5})?$/"; reference:url,unit42.paloaltonetworks.com/gasket-and-magicsocks-tools-install-mespinoza-ransomware/; classtype:command-and-control; sid:2033341; rev:1; metadata:created_at 2021_07_15, malware_family Gasket, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_07_15;)

Metadata

created at2021_07_15
malware familyGasket
confidenceHigh
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2021_07_15

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!