🐾 - ☠ DNS request 🌐 - 🎛 C2 🚪 Loader Zloader / Bazaloader -> Rançongiciel Ryuk 🔒
Sourcepawpatrules
CreatedOctober 23, 2020
UpdatedOctober 23, 2020
Classificationtrojan-activity
alert dns any any -> any any (msg:"🐾 - ☠ DNS request 🌐 - 🎛 C2 🚪 Loader Zloader / Bazaloader -> Rançongiciel Ryuk 🔒"; flow:to_server, stateless; dns_query; content:"vinohi.xyz"; nocase; reference:url,https://www.virustotal.com/gui/file/327da452b8c86ed8910056646771de8fb92a928c3d135efb2d41e6cb26806382/community; reference:url,https://www.joesandbox.com/analysis/507314#iocs; reference:url,https://bazaar.abuse.ch/sample/327da452b8c86ed8910056646771de8fb92a928c3d135efb2d41e6cb26806382/; reference:url,https://malpedia.caad.fkie.fraunhofer.de/details/win.zloader; metadata:created_at 2020_10_23, updated_at 2020_10_23; sid:3321233; rev:1; classtype:trojan-activity;)
References
Metadata
created at2020_10_23
updated at2020_10_23
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!