alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|02 09 00|"; distance:17; within:3; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; distance:0; content:!"|0a|Some-State"; distance:1; within:11; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:10; metadata:attack_target Client_Endpoint, created_at 2014_12_02, deployment Perimeter, former_category MALWARE, performance_impact Moderate, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2022_06_27;)

Added 2022-06-27 18:31:05 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|02 09 00|"; distance:17; within:3; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; distance:0; content:!"|0a|Some-State"; distance:1; within:11; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:10; metadata:attack_target Client_Endpoint, created_at 2014_12_02, deployment Perimeter, former_category MALWARE, performance_impact Moderate, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2022_03_31;)

Added 2022-03-31 18:11:49 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,to_client; content:"|06 03 55 04 08|"; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; tls_cert_subject; content:"C=AU"; content:!"ST=Some-State"; tls_cert_serial; content:"00:"; depth:3; isdataat:!24,relative; classtype:trojan-activity; sid:2019833; rev:9; metadata:attack_target Client_Endpoint, created_at 2014_12_02, deployment Perimeter, former_category MALWARE, performance_impact Moderate, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2022_03_27;)

Added 2022-03-27 11:31:19 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,to_client; content:"|06 03 55 04 08|"; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; tls_cert_subject; content:"C=AU"; content:!"ST=Some-State"; classtype:trojan-activity; sid:2019833; rev:8; metadata:attack_target Client_Endpoint, created_at 2014_12_02, deployment Perimeter, former_category MALWARE, performance_impact Moderate, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2022_03_19;)

Added 2022-03-21 18:45:53 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|02 09 00|"; distance:17; within:3; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; distance:0; content:!"|0a|Some-State"; distance:1; within:11; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:7; metadata:attack_target Client_Endpoint, created_at 2014_12_02, deployment Perimeter, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2016_07_01;)

Added 2021-09-21 19:59:44 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|02 09 00|"; distance:17; within:3; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; distance:0; content:!"|0a|Some-State"; distance:1; within:11; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:7; metadata:attack_target Client_Endpoint, created_at 2014_12_01, deployment Perimeter, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2016_07_01;)

Added 2020-08-05 19:10:34 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|02 09 00|"; distance:17; within:3; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; distance:0; content:!"|0a|Some-State"; distance:1; within:11; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:7; metadata:attack_target Client_Endpoint, deployment Perimeter, tag SSL_Malicious_Cert, signature_severity Major, created_at 2014_12_01, updated_at 2016_07_01;)

Added 2017-08-07 21:14:10 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|02 09 00|"; distance:17; within:3; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; distance:0; content:!"|0a|Some-State"; distance:1; within:11; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:7;)

Added 2015-01-19 18:12:38 UTC


alert tls $EXTERNAL_NET [443,4443] -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|02 09 00|"; distance:17; within:3; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; distance:0; pcre:"/^.{2}(?=[A-Z]{0,32}[^A-Z01])(?P[^01]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:6;)

Added 2014-12-04 18:40:20 UTC


alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; pcre:"/^.{2}(?=[a-z\x7f-\xff]{0,32}[0-9\x7f-\xff])(?P[a-z0-9\x7f-\xff]{4,33}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:5;)

Added 2014-12-03 18:49:35 UTC


alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET TROJAN Possible Dyre SSL Cert (fake state)"; flow:established,from_server; content:"|16|"; content:"|0b|"; within:8; content:"|06 03 55 04 06 13 02 41 55|"; distance:0; content:"|06 03 55 04 08|"; pcre:"/^.{2}(?=[a-z\x7f-\xff]{0,30}\d)(?P[a-z0-9\x7f-\xff]{4,31}[01]).+?\x06\x03\x55\x04\x08.{2}(?P=var)/Rs"; classtype:trojan-activity; sid:2019833; rev:4;)

Added 2014-12-01 18:30:54 UTC


Topic revision: r1 - 2022-06-27 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats