๐พ - ๐จ Suspicious OpenSSL demo TLS Certificate with the same informations in subject and issuer including > Internet Widgits Pty Ltd - Possible Trickbot or BumbleBee ๐ฟ C2 Server
Sourcepawpatrules
CreatedApril 2, 2022
UpdatedDecember 6, 2022
Classificationtrojan-activity
alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"๐พ - ๐จ Suspicious OpenSSL demo TLS Certificate with the same informations in subject and issuer including > Internet Widgits Pty Ltd - Possible Trickbot or BumbleBee ๐ฟ C2 Server"; flow:established,to_client; tls.cert_subject; content:"C=AU"; content:"ST=Some-State"; content:"O=Internet Widgits Pty Ltd"; tls.cert_issuer; content:"C=AU"; content:"ST=Some-State"; content:"O=Internet Widgits Pty Ltd"; reference:url,https://malpedia.caad.fkie.fraunhofer.de/details/win.trickbot; reference:url,https://malpedia.caad.fkie.fraunhofer.de/details/win.bumblebee; metadata:created_at 2022_04_02, updated_at 2022_12_06; sid:3300671; rev:3; classtype:trojan-activity;)
References
Metadata
created at2022_04_02
updated at2022_12_06
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!