alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; reference:url,forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:created_at 2018_08_23, deployment Perimeter, former_category MALWARE, performance_impact Moderate, signature_severity Major, updated_at 2020_11_19;)

Added 2020-11-19 18:26:23 UTC


alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; reference:url,forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:created_at 2018_08_23, deployment Perimeter, former_category MALWARE, performance_impact Moderate, signature_severity Major, updated_at 2020_08_19;)

Added 2020-08-19 18:14:31 UTC


alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; reference:url,forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:created_at 2018_08_23, deployment Perimeter, former_category MALWARE, performance_impact Moderate, signature_severity Major, updated_at 2019_09_28;)

Added 2020-08-05 19:15:05 UTC


alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; metadata: former_category MALWARE; reference:url,forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:deployment Perimeter, signature_severity Major, created_at 2018_08_23, performance_impact Moderate, updated_at 2019_09_28;)

Added 2019-10-01 08:29:06 UTC


alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; metadata: former_category MALWARE; reference:url,forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:deployment Perimeter, signature_severity Major, created_at 2018_08_23, performance_impact Moderate, updated_at 2019_09_28;)

Added 2019-10-01 04:23:30 UTC


alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; metadata: former_category MALWARE; reference:url,forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:deployment Perimeter, signature_severity Major, created_at 2018_08_23, performance_impact Moderate, updated_at 2018_08_23;)

Added 2019-08-28 19:02:04 UTC


alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; metadata: former_category TROJAN; reference:url,https://forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:deployment Perimeter, signature_severity Major, created_at 2018_08_23, performance_impact Moderate, updated_at 2018_08_23;)

Added 2018-09-13 19:55:07 UTC


Added 2018-09-13 18:02:26 UTC


alert http $HOME_NET any -> any any (msg:"ET TROJAN [PT MALWARE] Hacked Mikrotik C2 Request"; flow:established, to_server; content:"GET"; http_method; content:"/mikrotik.php"; http_uri; isdataat:!1,relative; content:"Mikrotik/6.x Fetch"; http_user_agent; depth:18; isdataat:!1,relative; fast_pattern; http_header_names; content:!"Accept"; content:!"Referer"; threshold:type threshold, track by_src, count 1, seconds 35; metadata: former_category TROJAN; reference:url,https://forum.mikrotik.com/viewtopic.php?t=137217; classtype:trojan-activity; sid:2026027; rev:2; metadata:deployment Perimeter, signature_severity Major, created_at 2018_08_23, performance_impact Moderate, updated_at 2018_08_23;)

Added 2018-08-23 18:13:09 UTC


Topic revision: r1 - 2020-11-19 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats