ET MALWARE ContEXE Stealer Data Exfiltration Attempt M2
Query · suricata
flow:established,to_server;
xbits:isset,ET.ContEXE_Stealer,track ip_pair;
http.method;
content:"PUT";
http.uri;
content:"/v1/backup/"; startswith;
pcre:"/^[a-f0-9]{8}-(?:[a-f0-9]{4}-){3}[a-f0-9]{12}\x22/R";
content:"/part|3f|name|3d|PC_INFO"; fast_pattern;
http.request_body;
content:"PK|03 04|"; startswith;
content:"PC_INFO.txt";
content:"machine_id|3d|";
content:"tag|3d|";
content:"agent|3d|";
target:src_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.ContEXE_Stealer