ET MALWARE Diamotrix POST Request M3

SID: 2063121Rev: 19 views
Sourceet/open
CreatedJune 20, 2025
UpdatedJune 20, 2025
Classificationtrojan-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Diamotrix POST Request M3"; flow:established,to_server; http.method; content:"POST"; http.uri; content:".php"; endswith; http.user_agent; bsize:74; content:"Mozilla/5.0|20 28|Windows NT 10.0|3b 20|Win64|3b 20|x64|3b 20|Trident/7.0|3b 20|rv:11.0|29 20|like Gecko"; fast_pattern; http.content_len; byte_test:0,<,100,0,string,dec; http.header_names; content:"|0d 0a|User-Agent|0d 0a|Host|0d 0a|Content-Length|0d 0a|Cache-Control|0d 0a 0d 0a|"; reference:md5,0e439843e068d7f1055ec05e03483d27; reference:url,app.any.run/tasks/0160cbae-ddcd-436e-a8be-280f024b47af; classtype:trojan-activity; sid:2063121; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Windows_10, attack_target Client_and_Server, tls_state plaintext, created_at 2025_06_20, deployment Perimeter, malware_family DiamotrixClipper, performance_impact Low, confidence High, signature_severity Major, tag InfoStealer, updated_at 2025_06_20, mitre_tactic_id TA0011, mitre_tactic_name Command_And_Control, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel; target:src_ip;)

Metadata

affected productWindows_10
attack targetClient_and_Server
tls stateplaintext
created at2025_06_20
deploymentPerimeter
malware familyDiamotrixClipper
performance impactLow
confidenceHigh
signature severityMajor
tagInfoStealer
updated at2025_06_20
mitre tactic idTA0011
mitre tactic nameCommand_And_Control
mitre technique idT1041
mitre technique nameExfiltration_Over_C2_Channel

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!