ET MALWARE RevStealer dl_exec Command from C2
Query · suricata
flow:established,to_client; flowbits:isset,ET.RevStealer.Sync; http.stat_code; content:"200"; http.response_body; content:"|22|tasks|22|"; content:"|22|action|22 3a 22|dl_exec|22|"; fast_pattern; content:"|22|dl|22 3a 22|"; content:"|22|dest|22 3a 22|"; content:"|22|cmdline|22 3a 22|"; target:src_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.RevStealer.Sync