ET MALWARE Win32/NetDooka Framework RAT Sending System Information M2
Query · suricata
flow:established,to_server;
flowbits:isset,ET.Netbooka.SessionIDSent;
content:"|90 01 00 00|"; fast_pattern;
content:"|00 00|"; distance:2; within:2;
content:"|00 00 00|"; distance:1; within:3;
pcre:"/^(?:[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})\x7c/R";
content:"|7c|"; distance:0;
content:"|7c|"; distance:2; within:1;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.Netbooka.SessionIDSent