ET MALWARE HailBot Server Response


Query · suricata

flow:established,to_server;
content:"|57 48 4f 20 54 48 45 20 48 45 4c 4c 20 41 52 45 20 59 4f 55 3f 20 54 45 4c 4c 20 4d 45 20 59 4f 55 52 20 4e 41 4d 45 21 20|";
Raw source ET MALWARE HailBot Server Response · Suricata
Esc
Published by Emerging Threats Open ↗, licensed under BSD 3-Clause ↗. Line breaks added for readability; the rule is otherwise unchanged.
alert tcp-pkt $HOME_NET any -> $EXTERNAL_NET any (
    msg:"ET MALWARE HailBot Server Response";
    flow:established,to_server;
    content:"|57 48 4f 20 54 48 45 20 48 45 4c 4c 20 41 52 45 20 59 4f 55 3f 20 54 45 4c 4c 20 4d 45 20 59 4f 55 52 20 4e 41 4d 45 21 20|";
    reference:url,nsfocusglobal.com/mirai-botnets-new-wave-hailbot-kiraibot-catddos-and-their-fierce-onslaught/;
    classtype:trojan-activity;
    sid:2050065; rev:1;
    metadata:attack_target Networking_Equipment, created_at 2024_01_12, deployment Perimeter, malware_family Mirai, malware_family hailBot, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_01_12;
)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.