BACKDOOR [PTsecurity] GoRed Request
Sourceptrules/open
CreatedOctober 9, 2025
UpdatedOctober 9, 2025
Classificationtrojan-activity
alert tcp any any -> any any (msg:"BACKDOOR [PTsecurity] GoRed Request"; flow:established, to_server; http.method; content:"GET"; http.uri; content:"/api/config"; depth:11; isdataat:!1, relative; http.header; content:"User-Agent: Go-http-client/"; content:"Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9"; distance:0; content:"Client-Id: "; distance:0; content:"Accept-Encoding: gzip"; distance:0; content:!"Referer"; reference:url, https://app.any.run/tasks/e94958c4-37a6-4f46-9098-b90fb36ae266; reference:url, rules.ptsecurity.com; classtype:trojan-activity; sid:10011377; rev:1;)
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!