# Rule Signatures

**URL:** https://community.emergingthreats.net/c/rule-sigs/11.md

[Latest](https://community.emergingthreats.net/latest.md) · [Categories](https://community.emergingthreats.net/categories.md) · [Tags](https://community.emergingthreats.net/tags.md)

---

## [About the Rule Signatures category](https://community.emergingthreats.net/t/about-the-rule-signatures-category/35)

<div class="topic-metadata">

**Author:** [@dkaczmark](https://community.emergingthreats.net/u/dkaczmark)\
**Replies:** 0

</div>

Discussion for Suricata and Snort rule signatures.

---

## [SIGS: SloppyRAT](https://community.emergingthreats.net/t/sigs-sloppyrat/3451)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [September 21, 2026, 8:49pm UTC](https://community.emergingthreats.net/t/sigs-sloppyrat/3451 "2026-09-21T20:49:16Z")

</div>

From SloppyRAT: A New Tool For Ransomware Attacks | ThreatLabz . UPDATE: I will keep these here in case but it does use certificate pinning likely making these unusable and having to fallback on encrypted traffic analyti…

---

## [Why ET rules used hex bytes instead of the original characters?](https://community.emergingthreats.net/t/why-et-rules-used-hex-bytes-instead-of-the-original-characters/3423)

<div class="topic-metadata">

**Author:** [@Sam\_Freeman](https://community.emergingthreats.net/u/Sam_Freeman)\
**Replies:** 4\
**Last updated:** [August 24, 2026, 8:09am UTC](https://community.emergingthreats.net/t/why-et-rules-used-hex-bytes-instead-of-the-original-characters/3423 "2026-08-24T08:09:51Z")

</div>

Hello everyone! While studying the rules from Emerging Threats, I noticed one peculiarity. In the rules, instead of the original symbols (for example, “.”) their hexadecimal byte values are used. Example Rules: alert…

---

## [False positive 2035595 - zgRAT / PureRAT confusion](https://community.emergingthreats.net/t/false-positive-2035595-zgrat-purerat-confusion/3393)

<div class="topic-metadata">

**Author:** [@erik4711](https://community.emergingthreats.net/u/erik4711)\
**Replies:** 3\
**Last updated:** [August 9, 2026, 8:19pm UTC](https://community.emergingthreats.net/t/false-positive-2035595-zgrat-purerat-confusion/3393 "2026-08-09T20:19:56Z")

</div>

I see rule 2035595 “ET MALWARE Generic AsyncRAT/zgRAT Style SSL Cert” getting triggered every now and then, but never for zgRAT traffic. It typically triggers when there’s PureRAT C2 traffic. I think I might have seen it…

---

## [SIG:ET HUNTING Possible Sliver Age and Minisign Key Material in Internal TCP Stream](https://community.emergingthreats.net/t/sig-et-hunting-possible-sliver-age-and-minisign-key-material-in-internal-tcp-stream/3352)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 2:21am UTC](https://community.emergingthreats.net/t/sig-et-hunting-possible-sliver-age-and-minisign-key-material-in-internal-tcp-stream/3352 "2026-06-10T02:21:20Z")

</div>

SIG: ET HUNTING Possible Sliver Age and Minisign Key Material in Internal TCP Stream Hi all, I wanted to share a Suricata hunting rule and an anonymized proof PCAP for review. The rule looks for age style public key mat…

---

## [Suricata.eve.alert.severity vs metadata's signature\_severity](https://community.emergingthreats.net/t/suricata-eve-alert-severity-vs-metadatas-signature-severity/3343)

<div class="topic-metadata">

**Author:** [@jannitand](https://community.emergingthreats.net/u/jannitand)\
**Replies:** 1\
**Last updated:** [June 9, 2026, 7:17pm UTC](https://community.emergingthreats.net/t/suricata-eve-alert-severity-vs-metadatas-signature-severity/3343 "2026-06-09T19:17:46Z")

</div>

Hello, and my apologies if the question is too silly. We are seeing alerts with alert.severity = 1 and signature\_severity = Informational How are the suricata.eve.alert.severity related (if they are) with the rule’s m…

---

## [SIG: ET TROJAN Gamaredon.APT GammaLoad Stage 1 User-Agent Structure](https://community.emergingthreats.net/t/sig-et-trojan-gamaredon-apt-gammaload-stage-1-user-agent-structure/3346)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 0\
**Last updated:** [June 4, 2026, 1:44pm UTC](https://community.emergingthreats.net/t/sig-et-trojan-gamaredon-apt-gammaload-stage-1-user-agent-structure/3346 "2026-06-04T13:44:48Z")

</div>

See reference for details. One note. on the sig it doesn’t appear to be showing the wildcard matching before and after the PCRE so that may need to be added (the asterisk) but we need to match the previous and ending of …

---

## [SIG: EarthWorm Reverse SOCKS Handshake and Tunnel Sequence Detection](https://community.emergingthreats.net/t/sig-earthworm-reverse-socks-handshake-and-tunnel-sequence-detection/3314)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 6\
**Last updated:** [May 27, 2026, 12:42am UTC](https://community.emergingthreats.net/t/sig-earthworm-reverse-socks-handshake-and-tunnel-sequence-detection/3314 "2026-05-27T00:42:18Z")

</div>

EarthWorm Research Lineage, Protocol Grounding, and Sample PCAP Set Hi all, I wanted to share some background on how this research thread came together, the protocol grounding behind the detections, and the sample PCAP s…

---

## [SIG: BPFDoor icmpShell ICMP artifacts from Rapid7 whitepaper](https://community.emergingthreats.net/t/sig-bpfdoor-icmpshell-icmp-artifacts-from-rapid7-whitepaper/3271)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 12\
**Last updated:** [May 14, 2026, 8:50pm UTC](https://community.emergingthreats.net/t/sig-bpfdoor-icmpshell-icmp-artifacts-from-rapid7-whitepaper/3271 "2026-05-14T20:50:08Z")

</div>

@bingohotdog I put together a small BPFDoor ICMP lab and wanted to share a few tested rule ideas based on a recent Rapid7 whitepaper (link in rules). I built a minimal PCAP to exercise the icmpShell related behaviors de…

---

## [SID 2069172 Alerts on Benign Activity](https://community.emergingthreats.net/t/sid-2069172-alerts-on-benign-activity/3286)

<div class="topic-metadata">

**Author:** [@segers](https://community.emergingthreats.net/u/segers)\
**Replies:** 1\
**Last updated:** [May 8, 2026, 9:26pm UTC](https://community.emergingthreats.net/t/sid-2069172-alerts-on-benign-activity/3286 "2026-05-08T21:26:20Z")

</div>

This alerted hundreds of times in our environment, mostly from Windows PCs; all of it appears to be benign. I compared the PCAPs from our alerts to the signature, but I’m not sure what could be changed in the signature.

---

## [Rule 2687428 VMware vCenter DCERPC Out-of-Bounds Write (CVE-2023-34048)](https://community.emergingthreats.net/t/rule-2687428-vmware-vcenter-dcerpc-out-of-bounds-write-cve-2023-34048/3280)

<div class="topic-metadata">

**Author:** [@James\_inthe\_box](https://community.emergingthreats.net/u/James_inthe_box)\
**Replies:** 3\
**Last updated:** [May 7, 2026, 2:49pm UTC](https://community.emergingthreats.net/t/rule-2687428-vmware-vcenter-dcerpc-out-of-bounds-write-cve-2023-34048/3280 "2026-05-07T14:49:34Z")

</div>

Lots of FP’s on this rule starting as soon as I updated the rules, no pcaps sorry.

---

## [SIG: Suspicious File Delivery from Cloudflare Family Host](https://community.emergingthreats.net/t/sig-suspicious-file-delivery-from-cloudflare-family-host/3246)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 7\
**Last updated:** [April 10, 2026, 5:40pm UTC](https://community.emergingthreats.net/t/sig-suspicious-file-delivery-from-cloudflare-family-host/3246 "2026-04-10T17:40:55Z")

</div>

alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:“LOCAL suspicious file delivery from targeted Cloudflare-family host”; flow:to\_server,established; http.host; pcre:“/^(?:(?:\[A-Za-z0-9-\]+.)\*trycloudflare.com|(?:\[A-Za-z0-…

---

## [SIGS: PoC for Axios NPM package supply chain compromise](https://community.emergingthreats.net/t/sigs-poc-for-axios-npm-package-supply-chain-compromise/3248)

<div class="topic-metadata">

**Author:** [@n0pth](https://community.emergingthreats.net/u/n0pth)\
**Replies:** 3\
**Last updated:** [April 1, 2026, 9:47pm UTC](https://community.emergingthreats.net/t/sigs-poc-for-axios-npm-package-supply-chain-compromise/3248 "2026-04-01T21:47:19Z")

</div>

Signature proposal based on the following research One of the most popular JavaScript packages on earth Axios has been compromised | OpenSourceMalware (disclaimer: i’m not the author). NOTE: Signature SIDs need proper a…

---

## [SIGS: ET TROJAN MuddyWatter HTTP\_VIP Backdoor](https://community.emergingthreats.net/t/sigs-et-trojan-muddywatter-http-vip-backdoor/3220)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 1\
**Last updated:** [March 4, 2026, 6:05pm UTC](https://community.emergingthreats.net/t/sigs-et-trojan-muddywatter-http-vip-backdoor/3220 "2026-03-04T18:05:56Z")

</div>

requires decryption c91413ad7c94c0e2694862b9d671d1204873bf65576ba2cb91fbd562a4ccf79b | Triage alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:“ET TROJAN MuddyWatter HTTP\_VIP Backdoor POST”; flow:established,to\_server;…

---

## [Possibly incorrect domain for ET ADWARE\_PUP signature](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211)

<div class="topic-metadata">

**Author:** [@starbuck](https://community.emergingthreats.net/u/starbuck)\
**Replies:** 2\
**Last updated:** [February 25, 2026, 8:11pm UTC](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211 "2026-02-25T20:11:20Z")

</div>

Hiya, our team received an alert for the signature ET ADWARE\_PUP Observed DNS Query to Passive Income App Domain (honeybook .com) which when I looked at the signature for contains the following: alert dns $HOME\_NET any…

---

## [Idea for new rules](https://community.emergingthreats.net/t/idea-for-new-rules/3186)

<div class="topic-metadata">

**Author:** [@pedrinazziM](https://community.emergingthreats.net/u/pedrinazziM)\
**Replies:** 0\
**Last updated:** [February 4, 2026, 8:45pm UTC](https://community.emergingthreats.net/t/idea-for-new-rules/3186 "2026-02-04T20:45:26Z")

</div>

Hello, I saw that datadome has a nice collection of crawlers (AI ones as well!) https://datadome.co/bots/. It could be interesting to add new detections based on this user agents list. Thanks!

---

## [Phishing / Crypto Wallet Drainer - psyopanime.net](https://community.emergingthreats.net/t/phishing-crypto-wallet-drainer-psyopanime-net/3166)

<div class="topic-metadata">

**Author:** [@tetsuoai](https://community.emergingthreats.net/u/tetsuoai)\
**Replies:** 2\
**Last updated:** [January 15, 2026, 10:16pm UTC](https://community.emergingthreats.net/t/phishing-crypto-wallet-drainer-psyopanime-net/3166 "2026-01-15T22:16:43Z")

</div>

Cloned phishing site targeting Solana users. Injects IPFS-hosted wallet drainer. Domain: psyopanime.net Malicious behavior: Loads drainer via /secureproxy?s=%2Fipfs%2F\_qEVAUVavvzeiYiasp2KRw7531dfc2b686e4c47507eec9ad…

---

## [Wrong malware family attribution 123Stealer](https://community.emergingthreats.net/t/wrong-malware-family-attribution-123stealer/3168)

<div class="topic-metadata">

**Author:** [@chekin88](https://community.emergingthreats.net/u/chekin88)\
**Replies:** 1\
**Last updated:** [January 15, 2026, 8:54pm UTC](https://community.emergingthreats.net/t/wrong-malware-family-attribution-123stealer/3168 "2026-01-15T20:54:20Z")

</div>

Hi! Our network malware detection team discovered potential incorrect attribution of a malware family in the signatures: ET MALWARE 123Stealer Victim CnC Checkin (POST) sid: 2066685 ET MALWARE 123Stealer Victim CnC Ch…

---

## [Closer cooperation between OPNsense and Suricata – TLS traffic decryption discussion](https://community.emergingthreats.net/t/closer-cooperation-between-opnsense-and-suricata-tls-traffic-decryption-discussion/3149)

<div class="topic-metadata">

**Author:** [@captcher2025](https://community.emergingthreats.net/u/captcher2025)\
**Replies:** 0\
**Last updated:** [December 24, 2025, 10:17am UTC](https://community.emergingthreats.net/t/closer-cooperation-between-opnsense-and-suricata-tls-traffic-decryption-discussion/3149 "2025-12-24T10:17:47Z")

</div>

Hello everyone, I would like to start a discussion about a topic that I believe is becoming increasingly important, especially when using Suricata in combination with OPNsense. I am aware that for known malware there i…

---

## [SIGS: CastleLoader/RAT](https://community.emergingthreats.net/t/sigs-castleloader-rat/3130)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 5\
**Last updated:** [December 19, 2025, 12:19am UTC](https://community.emergingthreats.net/t/sigs-castleloader-rat/3130 "2025-12-19T00:19:59Z")

</div>

Hi, At the end of this recordedfuture report is snort rules for CastleLoader and CastleRAT

---

## [PowerShell Malware from 147.45.178.149](https://community.emergingthreats.net/t/powershell-malware-from-147-45-178-149/3139)

<div class="topic-metadata">

**Author:** [@pacodiazz](https://community.emergingthreats.net/u/pacodiazz)\
**Replies:** 2\
**Last updated:** [December 18, 2025, 10:54pm UTC](https://community.emergingthreats.net/t/powershell-malware-from-147-45-178-149/3139 "2025-12-18T22:54:33Z")

</div>

(topic deleted by author)

---

## [2010677 ET MALWARE Suspicious User-Agent (My Session)](https://community.emergingthreats.net/t/2010677-et-malware-suspicious-user-agent-my-session/3127)

<div class="topic-metadata">

**Author:** [@segers](https://community.emergingthreats.net/u/segers)\
**Replies:** 4\
**Last updated:** [December 5, 2025, 7:00pm UTC](https://community.emergingthreats.net/t/2010677-et-malware-suspicious-user-agent-my-session/3127 "2025-12-05T19:00:49Z")

</div>

Alerting on legitimate outbound traffic from Aquaveo software.

---

## [AURA stealer](https://community.emergingthreats.net/t/aura-stealer/3108)

<div class="topic-metadata">

**Author:** [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Replies:** 7\
**Last updated:** [November 25, 2025, 4:26pm UTC](https://community.emergingthreats.net/t/aura-stealer/3108 "2025-11-25T16:26:00Z")

</div>

I am very sceptical about everything that is detected as Lumma Stealer since September 2025, when the administration of Lumma decided to vanish. Since that moment, everything related to Lumma should be thougth twice or e…

---

## [Suricata not detecting attacks using emerging threats](https://community.emergingthreats.net/t/suricata-not-detecting-attacks-using-emerging-threats/3100)

<div class="topic-metadata">

**Author:** [@Karl0Ken](https://community.emergingthreats.net/u/Karl0Ken)\
**Replies:** 0\
**Last updated:** [November 4, 2025, 11:38am UTC](https://community.emergingthreats.net/t/suricata-not-detecting-attacks-using-emerging-threats/3100 "2025-11-04T11:38:20Z")

</div>

I am currently working on my thesis, where I need a set of suricata alerts, labeled with event type (benign, attack). For this, I’ve been using the cic-ids2017 data set (https://www.unb.ca/cic/datasets/ids-2017.html). I …

---

## [False Positive 2065016 ET TROJAN BPFDoor Heartbeat (Outbound)](https://community.emergingthreats.net/t/false-positive-2065016-et-trojan-bpfdoor-heartbeat-outbound/3072)

<div class="topic-metadata">

**Author:** [@FastForward2025](https://community.emergingthreats.net/u/FastForward2025)\
**Replies:** 2\
**Last updated:** [October 6, 2025, 4:03pm UTC](https://community.emergingthreats.net/t/false-positive-2065016-et-trojan-bpfdoor-heartbeat-outbound/3072 "2025-10-06T16:03:47Z")

</div>

This rule triggered 2025/10/02 - 2025/10/03 on (Amazon) Ring Doorbell and Ring Floodlight devices. I spoke with Ring Customer Service who said the devices were performing a legitimate firmware update. 2065016 - ET TROJA…

---

## [False family: renaming rules from Lumma stealer to GCleaner loader](https://community.emergingthreats.net/t/false-family-renaming-rules-from-lumma-stealer-to-gcleaner-loader/3012)

<div class="topic-metadata">

**Author:** [@naumovax](https://community.emergingthreats.net/u/naumovax)\
**Replies:** 1\
**Last updated:** [September 8, 2025, 3:39pm UTC](https://community.emergingthreats.net/t/false-family-renaming-rules-from-lumma-stealer-to-gcleaner-loader/3012 "2025-09-08T15:39:15Z")

</div>

Hello! Our network malware detection team from PT found interesting falses in these Lumma rules: sid: 2064237 rev: 1 ET MALWARE Lumma Stealer CnC Checkin (/info) sid: 2064238 rev: 1 ET MALWARE Lumma Stealer CnC Server …

---

## [I want advice on Writing Better Detection Rules](https://community.emergingthreats.net/t/i-want-advice-on-writing-better-detection-rules/2987)

<div class="topic-metadata">

**Author:** [@Morgan](https://community.emergingthreats.net/u/Morgan)\
**Replies:** 1\
**Last updated:** [September 2, 2025, 6:12pm UTC](https://community.emergingthreats.net/t/i-want-advice-on-writing-better-detection-rules/2987 "2025-09-02T18:12:09Z")

</div>

Hi everyone, I am new to working with detection rules & signatures; so I thought this would be the best place to ask for some guidance. I have been experimenting with creating custom rules but I often get stuck when it…

---

## [SIG: ET HUNTING Possible JSFireTruck JavaScript Obfuscation](https://community.emergingthreats.net/t/sig-et-hunting-possible-jsfiretruck-javascript-obfuscation/2817)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [July 14, 2025, 9:12pm UTC](https://community.emergingthreats.net/t/sig-et-hunting-possible-jsfiretruck-javascript-obfuscation/2817 "2025-07-14T21:12:51Z")

</div>

The rendered squares here are actually \[ and \] alert tcp $EXTERNAL\_NET $HTTP\_PORTS → $HOME\_NET any (msg:“ET HUNTING Possible JSFireTruck JavaScript Obfuscation”; flow:established,to\_client; file\_data; content:“+”; conte…

---

## [Games and Myths: Mythstealer Spotted in the Wild](https://community.emergingthreats.net/t/games-and-myths-mythstealer-spotted-in-the-wild/2861)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 1\
**Last updated:** [July 1, 2025, 9:46pm UTC](https://community.emergingthreats.net/t/games-and-myths-mythstealer-spotted-in-the-wild/2861 "2025-07-01T21:46:34Z")

</div>

Myth Stealer Initial Investigation Hey folks, I just wanted to share an interesting investigation that started just yesterday, and resulted in some new detection in the ET ruleset, regarding “Myth Stealer”. I hadn’t sp…

---

## [Http.dottedquadhost and you](https://community.emergingthreats.net/t/http-dottedquadhost-and-you/2833)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 2\
**Last updated:** [July 1, 2025, 3:11pm UTC](https://community.emergingthreats.net/t/http-dottedquadhost-and-you/2833 "2025-07-01T15:11:04Z")

</div>

Hey hey folks, This post should be much shorter than the posts I typically deliver here. I just wanna make folks aware of some changes we made to some pretty old, but very valuable rules in the ET ruleset that tend to b…

[Next page](https://community.emergingthreats.net/c/rule-sigs/11.md?page=1)
