ET MALWARE ContEXE Stealer Data Exfiltration Attempt M1
Query · suricata
flow:established,to_server;
xbits:isset,ET.ContEXE_Stealer,track ip_pair;
http.method;
content:"PUT";
http.uri;
content:"/v1/backup/"; startswith;
pcre:"/^[a-f0-9]{8}-(?:[a-f0-9]{4}-){3}[a-f0-9]{12}\x22/R";
content:"/part|3f|name|3d|"; fast_pattern;
pcre:"/^(?:apps|Apps\x5fEdge|Browser\x5fcookies)/R";
http.request_body;
content:"PK|03 04|"; startswith;
target:src_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.ContEXE_Stealer