ET MALWARE Observed Malicious Mustang Panda APT Related SSL Cert (File Transfer Service)
Sourceet/open
CreatedDecember 16, 2022
UpdatedDecember 16, 2022
Classificationdomain-c2
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Observed Malicious Mustang Panda APT Related SSL Cert (File Transfer Service)"; flow:established,to_client; tls.cert_subject; content:"CN=45.134.83.29, O=File Transfer Service, OU=TLS Demo Cert, dnQualifier=mg3/mLPmK3YfX/MaJCs/mg=="; bsize:96; fast_pattern; reference:url,blogs.blackberry.com/en/2022/12/mustang-panda-uses-the-russian-ukrainian-war-to-attack-europe-and-asia-pacific-targets?s=09; classtype:domain-c2; sid:2042957; rev:1; metadata:attack_target Client_Endpoint, created_at 2022_12_16, deployment Perimeter, malware_family MustangPanda, confidence High, signature_severity Major, tag SSL_Malicious_Cert, tag TA416, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_12_16; target:src_ip;)
Metadata
attack targetClient_Endpoint
created at2022_12_16
deploymentPerimeter
malware familyMustangPanda
confidenceHigh
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2022_12_16
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!