ET MALWARE WallStealer CnC Response M1
Query · suricata
flow:established,to_client; flowbits:isset,ET.WallStealer.Checkin; http.stat_code; content:"200"; http.response_body; content:"|7b 22|status|22 3a 22|success|22 2c 22|message|22 3a 22|Paramater|20|received|2c 20|"; fast_pattern; startswith; content:"|20|collected|22 2c 22|ip|22 3a 22|"; within:30; content:"|22 2c 22|collected_count|22 3a|"; within:40; target:src_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.WallStealer.Checkin