ET HUNTING TA829 CnC Check-in With Unknown Identifier String
Sourceet/open
CreatedMay 29, 2025
UpdatedJune 27, 2025
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING TA829 CnC Check-in With Unknown Identifier String"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"|ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00|"; startswith; fast_pattern; pcre:"/^(?:(?:[A-Fa-f0-9]{2}\-){5}[A-Fa-f0-9]{2}|[A-Fa-f0-9]{16}|[A-Fa-f0-9]{63,65})\x40/R"; content:"|40|exist"; content:!"|40|RDPE1|40|"; content:!"|40|RUSTY|40|"; content:!"|40|VIVAT|40|"; content:!"|40|GAGA1|40|"; content:!"|40|CMPN1|40|"; classtype:command-and-control; sid:2063197; rev:1; metadata:attack_target Client_Endpoint, created_at 2025_05_29, deployment Perimeter, confidence High, signature_severity Major, tag TA829, updated_at 2025_06_27, former_sid 2862005; target:dest_ip;)
Metadata
attack targetClient_Endpoint
created at2025_05_29
deploymentPerimeter
confidenceHigh
signature severityMajor
tagTA829
updated at2025_06_27
former sid2862005
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!