ET MALWARE Carderbee APT Related Activity

SID: 2047715Rev: 12 views
History
Sourceet/open
CreatedAugust 23, 2023
UpdatedAugust 23, 2023
Classificationtrojan-activity
alert tcp $HOME_NET any -> $EXTERNAL_NET 443 (msg:"ET MALWARE Carderbee APT Related Activity"; flow:established,to_server; dsize:10; content:"hp_socket|00|"; fast_pattern; reference:md5,5a122e86a8f134e42ebae8510404df3d; reference:url,symantec-enterprise-blogs.security.com/blogs/threat-intelligence/carderbee-software-supply-chain-certificate-abuse; classtype:trojan-activity; sid:2047715; rev:1; metadata:attack_target Client_and_Server, created_at 2023_08_23, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_08_23; target:src_ip;)

Metadata

attack targetClient_and_Server
created at2023_08_23
deploymentPerimeter
performance impactLow
confidenceMedium
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2023_08_23

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!