# Rule Signatures

**URL:** https://community.emergingthreats.net/c/rule-sigs/11.md?page=2

[Latest](https://community.emergingthreats.net/latest.md) · [Categories](https://community.emergingthreats.net/categories.md) · [Tags](https://community.emergingthreats.net/tags.md)

**Page:** 3

---

## [ET INFO PE EXE or DLL Windows file download HTTP (2018959), and Recent Tuning](https://community.emergingthreats.net/t/et-info-pe-exe-or-dll-windows-file-download-http-2018959-and-recent-tuning/2366)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 0\
**Last updated:** [January 17, 2025, 6:36pm UTC](https://community.emergingthreats.net/t/et-info-pe-exe-or-dll-windows-file-download-http-2018959-and-recent-tuning/2366 "2025-01-17T18:36:01Z")

</div>

Hey folks, I want to talk about a False Positive Issue that I was troubleshooting on our community Discord. A couple of users had notified us of some false positives with the rule ET INFO PE EXE or DLL Windows file downl…

---

## [ET MALWARE Gamaredon.APT TryCloudFlare Activity](https://community.emergingthreats.net/t/et-malware-gamaredon-apt-trycloudflare-activity/2327)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [January 7, 2025, 9:07pm UTC](https://community.emergingthreats.net/t/et-malware-gamaredon-apt-trycloudflare-activity/2327 "2025-01-07T21:07:19Z")

</div>

This signature is mostly looking for a delimiter that appears in recent Gamareddon activity to trycloudflare domains (they used similar characters in http URIs in previous campaigns and I don’t think any legitimate user …

---

## [The Many CVEs of D-Link HNAP Command Injection](https://community.emergingthreats.net/t/the-many-cves-of-d-link-hnap-command-injection/2314)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 0\
**Last updated:** [January 2, 2025, 11:02pm UTC](https://community.emergingthreats.net/t/the-many-cves-of-d-link-hnap-command-injection/2314 "2025-01-02T23:02:18Z")

</div>

D-Link HNAP (Home Network Administration Protocol) Command Injection CVE-2015-2051, 2019-10891, 2022-37056, and 2024-33112 Happy New Year! Time to kick off with… more IoT vulnerabilities. I was surfing Mastodon today, lo…

---

## [ET SCAN ELF/Mirai Variant](https://community.emergingthreats.net/t/et-scan-elf-mirai-variant/2303)

<div class="topic-metadata">

**Author:** [@MalPRE](https://community.emergingthreats.net/u/MalPRE)\
**Replies:** 2\
**Last updated:** [December 31, 2024, 10:00pm UTC](https://community.emergingthreats.net/t/et-scan-elf-mirai-variant/2303 "2024-12-31T22:00:07Z")

</div>

We have recently detected a new wave of attacks using Mirai variants, and here are two notable rules: alert udp any any -\> any any (msg:"ET SCAN ELF/Mirai Variant UDP (Inbound)"; content:"|38 C4 FB 98 76 1F FC FE F4 00 …

---

## [SIGS: Zloader](https://community.emergingthreats.net/t/sigs-zloader/2268)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [December 17, 2024, 6:56pm UTC](https://community.emergingthreats.net/t/sigs-zloader/2268 "2024-12-17T18:56:51Z")

</div>

These signatures require TLS decryption. alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:“ET TROJAN Zloader Known User-Agent”; flow:established,to\_server; http.user\_agent; content:“PresidentPutin”; classtype:trojan-ac…

---

## [SIG: TryCloudFlare in SNI](https://community.emergingthreats.net/t/sig-trycloudflare-in-sni/2236)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 1\
**Last updated:** [December 10, 2024, 9:11pm UTC](https://community.emergingthreats.net/t/sig-trycloudflare-in-sni/2236 "2024-12-10T21:11:52Z")

</div>

alert tls $HOME\_NET any → $EXTERNAL\_NET any (msg:“ET HUNTING TryCloudFlare Domain in TLS SNI”; flow:established,to\_server; tls.sni; dotprefix; content:“.trycloudflare.com”; endswith; reference:url,Quick Tunnels · Cloudfl…

---

## [ET TROJAN Win32/BugSleep CnC Checkin](https://community.emergingthreats.net/t/et-trojan-win32-bugsleep-cnc-checkin/2097)

<div class="topic-metadata">

**Author:** [@network\_goblin](https://community.emergingthreats.net/u/network_goblin)\
**Replies:** 4\
**Last updated:** [November 2, 2024, 5:52pm UTC](https://community.emergingthreats.net/t/et-trojan-win32-bugsleep-cnc-checkin/2097 "2024-11-02T17:52:59Z")

</div>

This rule probably is missing the noalert as per the references in the rule. Right now, I’m seeing it fire a bunch of times on my networks. alert tcp $HOME\_NET any -\> $EXTERNAL\_NET 443 (msg:"ET TROJAN Win32/BugSleep CnC…

---

## [SIGS: Android/TrickMo.Banker](https://community.emergingthreats.net/t/sigs-android-trickmo-banker/2086)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [October 29, 2024, 7:10pm UTC](https://community.emergingthreats.net/t/sigs-android-trickmo-banker/2086 "2024-10-29T19:10:46Z")

</div>

alert tcp $HOME\_NET any → $EXTERNAL\_NET $HTTP\_PORTS (msg:“ET MOBILE\_MALWARE Android/TrickMo.Banker POST Request”; flow:established,to\_server; content:“POST”; http\_method; content:“|22|id|22|”; http\_client\_body; content:“…

---

## [Ailurophile Stealer](https://community.emergingthreats.net/t/ailurophile-stealer/2082)

<div class="topic-metadata">

**Author:** [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Replies:** 1\
**Last updated:** [October 28, 2024, 5:27pm UTC](https://community.emergingthreats.net/t/ailurophile-stealer/2082 "2024-10-28T17:27:38Z")

</div>

hello i just found these samples in the wild of ailurophile Stealer, a new malware that has no rule detection Analysis https://noogamotorsports.com/ZoomInstaller.exe Malicious activity - Interactive analysis ANY.RUN An…

---

## [Signature Mints Loader](https://community.emergingthreats.net/t/signature-mints-loader/2075)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 1\
**Last updated:** [October 25, 2024, 6:26pm UTC](https://community.emergingthreats.net/t/signature-mints-loader/2075 "2024-10-25T18:26:49Z")

</div>

alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:“ET MALWARE Mints.Loader GET Request”; flow:established,to\_server; content:“GET”; http\_method; content:“.php?s=mints”; http\_uri; fast\_pattern; content:“WindowsPowerShell/…

---

## [Privateloader](https://community.emergingthreats.net/t/privateloader/1226)

<div class="topic-metadata">

**Author:** [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Replies:** 5\
**Last updated:** [October 14, 2024, 6:46pm UTC](https://community.emergingthreats.net/t/privateloader/1226 "2024-10-14T18:46:43Z")

</div>

Privateloader is changing its behavior trying to evade detection and sandbox detonations. I’ve been observing this in the recent days and its time to update rules. A common detonation since this day is something like th…

---

## [\[False Positive\] ET INFO domain VirusTotal](https://community.emergingthreats.net/t/false-positive-et-info-domain-virustotal/2049)

<div class="topic-metadata">

**Author:** [@wnelson](https://community.emergingthreats.net/u/wnelson)\
**Replies:** 1\
**Last updated:** [October 14, 2024, 4:45pm UTC](https://community.emergingthreats.net/t/false-positive-et-info-domain-virustotal/2049 "2024-10-14T16:45:43Z")

</div>

VirusTotal is saying our domain keyauth.win is flagged for: ET INFO Fake Game Cheat Related Domain in DNS Lookup (keyauth .win) Our website is a legitimate software licensing API. We’re open-source and you can our …

---

## [PortStarter Backdoor Sigs](https://community.emergingthreats.net/t/portstarter-backdoor-sigs/2042)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 1\
**Last updated:** [October 10, 2024, 12:02pm UTC](https://community.emergingthreats.net/t/portstarter-backdoor-sigs/2042 "2024-10-10T12:02:47Z")

</div>

Used by ViceSociety/Rhysidia ransomware. More info here Advanced Cyber Threat Intelligence | Recorded Future (page 14). Additional Samples VirusTotal, VirusTotal I have noticed even though when I edit it the escaped dot…

---

## [Grimresource transformNode Obfuscation](https://community.emergingthreats.net/t/grimresource-transformnode-obfuscation/2037)

<div class="topic-metadata">

**Author:** [@rampage](https://community.emergingthreats.net/u/rampage)\
**Replies:** 5\
**Last updated:** [October 10, 2024, 6:35pm UTC](https://community.emergingthreats.net/t/grimresource-transformnode-obfuscation/2037 "2024-10-10T18:35:39Z")

</div>

Hello. I’d like to share a rule with the community and welcome feedback. I intend it to detect the transformNode Obfuscation used in the Grimresource sample analyzed by Elastic Security Labs GrimResource - Microsoft Man…

---

## [Signature: CleanUp Loader](https://community.emergingthreats.net/t/signature-cleanup-loader/2038)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [October 9, 2024, 8:39pm UTC](https://community.emergingthreats.net/t/signature-cleanup-loader/2038 "2024-10-09T20:39:37Z")

</div>

More info here https://go.recordedfuture.com/hubfs/reports/cta-2024-1009.pdf. This request is made over HTTPS so requires decryption to see. alert tcp $HOME\_NET any → EXTERNAL\_NET $HTTP\_PORTS (msg:“ET MALWARE CleanUp Lo…

---

## [Sid:2055984 Ivanti Cloud Service Appliance Authenticated Command Injection (CVE-2024-8190)](https://community.emergingthreats.net/t/sid-2055984-ivanti-cloud-service-appliance-authenticated-command-injection-cve-2024-8190/2011)

<div class="topic-metadata">

**Author:** [@rampage](https://community.emergingthreats.net/u/rampage)\
**Replies:** 1\
**Last updated:** [October 1, 2024, 7:57pm UTC](https://community.emergingthreats.net/t/sid-2055984-ivanti-cloud-service-appliance-authenticated-command-injection-cve-2024-8190/2011 "2024-10-01T19:57:05Z")

</div>

Greetings friends! sid:2055984 references www.horizon3.ai/attack-research/cisa-kev-cve-2024-8190-ivanti-csa-command-injection/, however it is not alerting on POST requests produced by the POC (GitHub - horizon3ai/CVE-20…

---

## [Poverty Stealer](https://community.emergingthreats.net/t/poverty-stealer/839)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 12\
**Last updated:** [September 17, 2024, 9:11pm UTC](https://community.emergingthreats.net/t/poverty-stealer/839 "2024-09-17T21:11:08Z")

</div>

Hey, and a few more rules for another stealer. I want to share with the community given the activity of the malware. Exfiltration is carried out through RAW TCP, port 2227. alert tcp any any -\> any 2227 (msg: "ET MAL…

---

## [FP? NanoLocker - SID: 2022331](https://community.emergingthreats.net/t/fp-nanolocker-sid-2022331/1963)

<div class="topic-metadata">

**Author:** [@network\_goblin](https://community.emergingthreats.net/u/network_goblin)\
**Replies:** 1\
**Last updated:** [September 12, 2024, 9:03pm UTC](https://community.emergingthreats.net/t/fp-nanolocker-sid-2022331/1963 "2024-09-12T21:03:18Z")

</div>

I have been reviewing Suricata alerts recently. I noticed that the follow side triggered on some Google LLC owned IPs: trojan.rules:12168:alert icmp $HOME\_NET any -\> $EXTERNAL\_NET any (msg:"ET TROJAN NanoLocker Check-in…

---

## [NMAP ruleset are FP?](https://community.emergingthreats.net/t/nmap-ruleset-are-fp/1945)

<div class="topic-metadata">

**Author:** [@jul10l1r43](https://community.emergingthreats.net/u/jul10l1r43)\
**Replies:** 1\
**Last updated:** [September 5, 2024, 12:59pm UTC](https://community.emergingthreats.net/t/nmap-ruleset-are-fp/1945 "2024-09-05T12:59:33Z")

</div>

Does anyone know why several rules that identified portscan were removed? 2009582 for example # alert tcp $EXTERNAL\_NET any -\> $HOME\_NET any (msg:"ET SCAN NMAP -sS window 1024"; fragbits:!D; dsize:0; flags:S,12; ack:0; …

---

## [DiamotrixClipper](https://community.emergingthreats.net/t/diamotrixclipper/1925)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 2\
**Last updated:** [August 30, 2024, 9:08pm UTC](https://community.emergingthreats.net/t/diamotrixclipper/1925 "2024-08-30T21:08:33Z")

</div>

Hi, together with @g0njxa we found a loader(Sniffthem/Tnaket) and a clipper (Diamotrix) here is the signature for the clipper: URI: alert http any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] Request a wallet for Diamo…

---

## [BadSpace Sigs](https://community.emergingthreats.net/t/badspace-sigs/1898)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 1\
**Last updated:** [August 19, 2024, 5:33pm UTC](https://community.emergingthreats.net/t/badspace-sigs/1898 "2024-08-19T17:33:29Z")

</div>

Hi, The BadSpace/WarmCookie sigs may need reworked or new ones. This is from PCAP Malware-Traffic-Analysis.net - 2024-08-15 - Traffic analysis exercise: WarmCookie). It is using 5.0 instead of 4.0. User-Agent: Mozilla …

---

## [Where to find details on each threat definition?](https://community.emergingthreats.net/t/where-to-find-details-on-each-threat-definition/1874)

<div class="topic-metadata">

**Author:** [@DVB](https://community.emergingthreats.net/u/DVB)\
**Replies:** 1\
**Last updated:** [August 5, 2024, 4:15pm UTC](https://community.emergingthreats.net/t/where-to-find-details-on-each-threat-definition/1874 "2024-08-05T16:15:29Z")

</div>

Does exist somewhere a place where I can read about a particular threat definition ID if I want to know more about?

---

## [Vidar Stealer](https://community.emergingthreats.net/t/vidar-stealer/1106)

<div class="topic-metadata">

**Author:** [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Replies:** 7\
**Last updated:** [July 15, 2024, 5:06pm UTC](https://community.emergingthreats.net/t/vidar-stealer/1106 "2024-07-15T17:06:49Z")

</div>

This is going to be controversial. Vidar Stealer made a 180 degree change in their C2 traffic. This is the official statement from their panel both in Russian (original) and English (Translated) 6.4 — Большое обновлени…

---

## [Metastealer v.5 TLS](https://community.emergingthreats.net/t/metastealer-v-5-tls/1800)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 6\
**Last updated:** [July 10, 2024, 3:13pm UTC](https://community.emergingthreats.net/t/metastealer-v-5-tls/1800 "2024-07-10T15:13:32Z")

</div>

Hello, there is a proposal to detect a metastealer that operates TLS encapsulated in MC-NMF (.NET Message Framing Protocol). The principle of the rule is based on matching the default certificate in the connection. I’m n…

---

## [Why not leverage Suricata datasets for IoC rules?](https://community.emergingthreats.net/t/why-not-leverage-suricata-datasets-for-ioc-rules/1797)

<div class="topic-metadata">

**Author:** [@chilton](https://community.emergingthreats.net/u/chilton)\
**Replies:** 1\
**Last updated:** [July 8, 2024, 5:56pm UTC](https://community.emergingthreats.net/t/why-not-leverage-suricata-datasets-for-ioc-rules/1797 "2024-07-08T17:56:46Z")

</div>

Why are IoC rulesets such as in ciarmy.rules still using regular Suricata rules? Wouldn’t it be much more efficient to use Suricata datasets for matching a huge number of IoCs? Or what am I missing?

---

## [Cryptbot Stealer - Update on Rules](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790)

<div class="topic-metadata">

**Author:** [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Replies:** 4\
**Last updated:** [July 5, 2024, 9:45pm UTC](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790 "2024-07-05T21:45:31Z")

</div>

Cryptbot Stealer has been switching its behavior in the past weeks from uploading logs to C2 on /gate.php to /zip.php. Maybe there are more changes. I believe this change has been completed and theres no rule detection …

---

## [ET POLICY Reserved Internal IP Traffic](https://community.emergingthreats.net/t/et-policy-reserved-internal-ip-traffic/1759)

<div class="topic-metadata">

**Author:** [@souha](https://community.emergingthreats.net/u/souha)\
**Replies:** 1\
**Last updated:** [June 24, 2024, 6:41pm UTC](https://community.emergingthreats.net/t/et-policy-reserved-internal-ip-traffic/1759 "2024-06-24T18:41:14Z")

</div>

any idea

---

## [False positive on rule #2032926](https://community.emergingthreats.net/t/false-positive-on-rule-2032926/1749)

<div class="topic-metadata">

**Author:** [@jimoe](https://community.emergingthreats.net/u/jimoe)\
**Replies:** 4\
**Last updated:** [June 23, 2024, 5:23pm UTC](https://community.emergingthreats.net/t/false-positive-on-rule-2032926/1749 "2024-06-23T17:23:40Z")

</div>

I occasionally see this in fast.log. It always occurs during a backup from the local system to a NFS volume. 06/21/2024-05:06:16.154024 \[\*\*\] \[1:2032926:2\] ET INFO Possible Overflow Attempt - Abnormally Large SMTP EHLO …

---

## [NjRAT variant - tXRAT v.2.3R](https://community.emergingthreats.net/t/njrat-variant-txrat-v-2-3r/1746)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 1\
**Last updated:** [June 21, 2024, 4:44pm UTC](https://community.emergingthreats.net/t/njrat-variant-txrat-v-2-3r/1746 "2024-06-21T16:44:11Z")

</div>

Hi, recently I discovered a modification of the famous rat NjRat, we could not detect it with the existing rules, so I propose several new ones (version obtained from traffic) NjRat Traffic example 155.ll|‘|’|VEVTVF9D…

---

## [False positives on hunting rule](https://community.emergingthreats.net/t/false-positives-on-hunting-rule/1741)

<div class="topic-metadata">

**Author:** [@beshbesh](https://community.emergingthreats.net/u/beshbesh)\
**Replies:** 2\
**Last updated:** [June 21, 2024, 3:40pm UTC](https://community.emergingthreats.net/t/false-positives-on-hunting-rule/1741 "2024-06-21T15:40:15Z")

</div>

Hello, The rule with 2011341, SID ET HUNTING Suspicious POST With Reference to WINDOWS Folder Possible Malware Infection seems to give me a false positive. When using Elastic and Winlogbeat to transfer logs over HTTP, t…

[Previous page](https://community.emergingthreats.net/c/rule-sigs/11.md?page=1)

[Next page](https://community.emergingthreats.net/c/rule-sigs/11.md?page=3)
