🐾 - 🚨 Meterpreter C2 session established from Windows 🪟 - 2024-02-20 - TA0011

SID: 3321306Rev: 2102 views
Sourcepawpatrules
CreatedJuly 25, 2024
UpdatedJuly 25, 2024
Classificationcommand-and-control
alert tcp any any -> any any (msg:"🐾 - 🚨 Meterpreter C2 session established from Windows 🪟 - 2024-02-20 - TA0011"; flow:to_client, stateless; content:"|4d 5a|"; startswith; content:"|50 45 00 00|"; content:"|4c 01|"; distance:0; content:"|f9 e6 d4 65|"; distance:2; fast_pattern; content:"|02 21|"; distance:10; content:"|0b 01|"; distance:0; reference:url,https://attack.mitre.org/tactics/TA0011/; reference:url,https://www.metasploit.com/; target:dest_ip; metadata:attack_target Client_and_Server, signature_severity Major, affected_product Windows_XP_Vista_7_8_10_11_Server_32_64_Bit, mitre_tactic_id TA0011, mitre_tactic_name Command_and_Control, mitre_technique_id T1071.001, mitre_technique_name Application_Layer_Protocol_Web_Protocols, former_category MALWARE, malware_family Metasploit, created_at 2024_07_25, updated_at 2024_07_25; sid:3321306; rev:2; classtype:command-and-control;)

Metadata

attack targetClient_and_Server
signature severityMajor
affected productWindows_XP_Vista_7_8_10_11_Server_32_64_Bit
mitre tactic idTA0011
mitre tactic nameCommand_and_Control
mitre technique idT1071.001
mitre technique nameApplication_Layer_Protocol_Web_Protocols
former categoryMALWARE
malware familyMetasploit
created at2024_07_25
updated at2024_07_25

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!