ET MALWARE Glove Stealer Data Exfiltration Attempt

SID: 2057790Rev: 110 views
Sourceet/open
CreatedNovember 22, 2024
UpdatedNovember 22, 2024
Classificationtrojan-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Glove Stealer Data Exfiltration Attempt"; flow:established,to_server; http.method; content:"POST"; http.header; content:"TimeStamp|3a 20|"; fast_pattern; http.header_names; content:"|0d 0a|TimeStamp|0d 0a|Cookie|0d 0a|"; reference:url,www.gendigital.com/blog/insights/research/glove-stealer; classtype:trojan-activity; sid:2057790; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Windows_11, attack_target Client_and_Server, tls_state TLSDecrypt, created_at 2024_11_22, deployment Perimeter, deployment SSLDecrypt, malware_family Glove_Stealer, performance_impact Low, confidence High, signature_severity Major, tag InfoStealer, updated_at 2024_11_22, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel; target:src_ip;)

Metadata

affected productWindows_11
attack targetClient_and_Server
tls stateTLSDecrypt
created at2024_11_22
deploymentSSLDecrypt
malware familyGlove_Stealer
performance impactLow
confidenceHigh
signature severityMajor
tagInfoStealer
updated at2024_11_22
mitre tactic idTA0010
mitre tactic nameExfiltration
mitre technique idT1041
mitre technique nameExfiltration_Over_C2_Channel

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!