ET MALWARE PeakLight/Emmenhtal Loader Payload Request

SID: 2055990Rev: 34 views
History
Sourceet/open
CreatedSeptember 18, 2024
UpdatedApril 15, 2025
Classificationtrojan-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE PeakLight/Emmenhtal Loader Payload Request"; flow:established,to_server; http.uri; content:"pdf|2e|lnk"; endswith; nocase; fast_pattern; http.user_agent; content:"Microsoft-WebDAV-MiniRedir"; startswith; reference:url,blog.sekoia.io/webdav-as-a-service-uncovering-the-infrastructure-behind-emmenhtal-loader-distribution; reference:url,orangecyberdefense.com/global/blog/cert-news/emmenhtal-a-little-known-loader-distributing-commodity-infostealers-worldwide; reference:url,cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware; classtype:trojan-activity; sid:2055990; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, tls_state plaintext, created_at 2024_09_18, deployment Perimeter, deprecation_reason Age, confidence High, signature_severity Major, tag c2, updated_at 2025_04_15, reviewed_at 2025_04_15, former_sid 2858394, mitre_tactic_id TA0011, mitre_tactic_name Command_And_Control, mitre_technique_id T1071, mitre_technique_name Application_Layer_Protocol;)

Metadata

affected productWindows_XP_Vista_7_8_10_Server_32_64_Bit
attack targetClient_Endpoint
tls stateplaintext
created at2024_09_18
deploymentPerimeter
deprecation reasonAge
confidenceHigh
signature severityMajor
tagc2
updated at2025_04_15
reviewed at2025_04_15
former sid2858394
mitre tactic idTA0011
mitre tactic nameCommand_And_Control
mitre technique idT1071
mitre technique nameApplication_Layer_Protocol

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!