ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (lkcharles .com)Source: et/open
alert tls $HOME_NET any -> $EXTERNAL_NET any (msg: "ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (lkcharles .com)"; flow: established,to_server; tls.sni; bsize: 13; content: "lkcharles.com"; fast_pattern; reference: url,malasada.tech/the-landupdate808-fake-update-variant/; classtype: exploit-kit; sid: 2061153; rev: 1; metadata: affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2025_03_27, deployment Perimeter, performance_impact Low, confidence High, signature_severity Minor, tag Exploit_Kit, tag LandUpdate808, tag compromised_website, updated_at 2025_03_27, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1189, mitre_technique_name Drive_by_Compromise;)
References | |
---|---|
URL | https://malasada.tech/the-landupdate808-fake-update-variant/ |
Metadata | |
---|---|
affected_product | Web_Browsers |
attack_target | Client_Endpoint |
created_at | 2025_03_27 |
deployment | Perimeter |
performance_impact | Low |
confidence | High |
signature_severity | Minor |
tag | Exploit_Kit |
tag | LandUpdate808 |
tag | compromised_website |
updated_at | 2025_03_27 |
mitre_tactic_id | TA0001 |
mitre_tactic_name | Initial_Access |
mitre_technique_id | T1189 |
mitre_technique_name | Drive_by_Compromise |
Views: 5