ET MALWARE Earth Minotaur MOONSHINE Exploit Kit URI Struct Detected
Sourceet/open
CreatedJanuary 2, 2025
UpdatedJanuary 2, 2025
Classificationtrojan-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Earth Minotaur MOONSHINE Exploit Kit URI Struct Detected"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/api/v1/things/web|3f|going|3d|wPol3ljdKj"; fast_pattern; startswith; reference:url,www.trendmicro.com/en_us/research/24/l/earth-minotaur.html; classtype:trojan-activity; sid:2058717; rev:1; metadata:affected_product Android, attack_target Mobile_Client, tls_state TLSDecrypt, created_at 2025_01_02, deployment Perimeter, deployment Internal, deployment SSLDecrypt, malware_family MOONSHINE, performance_impact Low, confidence High, signature_severity Major, tag Earth_Minotaur, updated_at 2025_01_02, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1189, mitre_technique_name Drive_by_Compromise;)
Metadata
affected productAndroid
attack targetMobile_Client
tls stateTLSDecrypt
created at2025_01_02
deploymentSSLDecrypt
malware familyMOONSHINE
performance impactLow
confidenceHigh
signature severityMajor
tagEarth_Minotaur
updated at2025_01_02
mitre tactic idTA0001
mitre tactic nameInitial_Access
mitre technique idT1189
mitre technique nameDrive_by_Compromise
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!