ET MALWARE Red Leaves magic packet response detected (APT10 implant)
Query · suricata
flowbits:isset,ncc.apt10.beacon_send; flow:established,to_client; dsize:12; content:"|7a 8d 9b dc|"; offset:4; depth:4; threshold:type limit, track by_dst, count 1, seconds 600;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ncc.apt10.beacon_send