# Rule Signatures

**URL:** https://community.emergingthreats.net/c/rule-sigs/11.md?page=5

[Latest](https://community.emergingthreats.net/latest.md) · [Categories](https://community.emergingthreats.net/categories.md) · [Tags](https://community.emergingthreats.net/tags.md)

**Page:** 6

---

## [TheBoxClipper](https://community.emergingthreats.net/t/theboxclipper/904)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 2\
**Last updated:** [August 30, 2023, 8:58pm UTC](https://community.emergingthreats.net/t/theboxclipper/904 "2023-08-30T20:58:53Z")

</div>

Hi, I decided to dedicate this rule to our good friend and researcher @James\_inthe\_box. He discovered the clipper and we wanted to come up with a name, so I decided)) Apparently, the request is hardcoded in the traffic…

---

## [RootTeam Stealer and overlap issues on Bandit Stealer rule detection](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744)

<div class="topic-metadata">

**Author:** [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Replies:** 7\
**Last updated:** [August 29, 2023, 5:41pm UTC](https://community.emergingthreats.net/t/rootteam-stealer-and-overlap-issues-on-bandit-stealer-rule-detection/744 "2023-08-29T17:41:56Z")

</div>

Hello Team, Recently a new stealer product was announced on the market and was discovered being distributed via Youtube compromised channels. Thanks to @AnFam17 for verifying such statement. Who said what on Twitter: “…

---

## [Mekotio](https://community.emergingthreats.net/t/mekotio/895)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 2\
**Last updated:** [August 24, 2023, 9:21pm UTC](https://community.emergingthreats.net/t/mekotio/895 "2023-08-24T21:21:07Z")

</div>

Hi, I propose a rule for the Mekotio banking trojan, which began to appear frequently with this traffic in our sandbox in August. Malware Reports - Online Malware Analysis Sandbox ← searching by tag alert tcp any any -\>…

---

## [Parallax Rat](https://community.emergingthreats.net/t/parallax-rat/850)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 3\
**Last updated:** [August 14, 2023, 9:54pm UTC](https://community.emergingthreats.net/t/parallax-rat/850 "2023-08-14T21:54:38Z")

</div>

Hi. Today we discussed parallax, and now I propose a rule similar to sid:2032526; but for all ports and without flowbit. alert tcp any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] Parallax RAT Check-In";flow: established…

---

## [SIG: CloudFlare Tunnel DNS Query For argotunnel.com](https://community.emergingthreats.net/t/sig-cloudflare-tunnel-dns-query-for-argotunnel-com/851)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [August 14, 2023, 8:07pm UTC](https://community.emergingthreats.net/t/sig-cloudflare-tunnel-dns-query-for-argotunnel-com/851 "2023-08-14T20:07:12Z")

</div>

alert udp $HOME\_NET any → any 53 (msg:“ET POLICY CloudFlare Tunnel DNS Query For argotunnel.com”; content:“|0A|argotunnel|03|com”; fast\_pattern:only; classtype:policy-violation; reference:url,Tunnel Vision: CloudflareD A…

---

## [DarkCloud](https://community.emergingthreats.net/t/darkcloud/844)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 2\
**Last updated:** [August 9, 2023, 7:58pm UTC](https://community.emergingthreats.net/t/darkcloud/844 "2023-08-09T19:58:27Z")

</div>

Hi, I noticed that the darkcloud stealer requests an external ip address with a custom header, and I suggest detecting it with the following rule: alert http any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] DarkCloud Exte…

---

## [Phemedrone Stealer](https://community.emergingthreats.net/t/phemedrone-stealer/838)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 1\
**Last updated:** [August 7, 2023, 9:52pm UTC](https://community.emergingthreats.net/t/phemedrone-stealer/838 "2023-08-07T21:52:59Z")

</div>

Hello, I propose a rule for phemedron stealer. Exfiltation is carried out through telegram. alert http any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] Phemedrone Stealer Exfiltration"; flow: established, to\_server; …

---

## [Possible FP - JA3 Hash - \[Abuse.ch\] Possible Adware](https://community.emergingthreats.net/t/possible-fp-ja3-hash-abuse-ch-possible-adware/825)

<div class="topic-metadata">

**Author:** [@erenhelm](https://community.emergingthreats.net/u/erenhelm)\
**Replies:** 1\
**Last updated:** [August 1, 2023, 6:53pm UTC](https://community.emergingthreats.net/t/possible-fp-ja3-hash-abuse-ch-possible-adware/825 "2023-08-01T18:53:25Z")

</div>

We are receiving alerts on this: alert tls $HOME\_NET any → $EXTERNAL\_NET any (msg:“ET JA3 Hash - \[Abuse.ch\] Possible Adware”; ja3\_hash; content:“bc6c386f480ee97b9d9e52d472b772d8”; reference:url,sslbl.abuse.ch/ja3-finger…

---

## [PennyWise Stealer - Update on rules](https://community.emergingthreats.net/t/pennywise-stealer-update-on-rules/812)

<div class="topic-metadata">

**Author:** [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Replies:** 2\
**Last updated:** [July 28, 2023, 10:14pm UTC](https://community.emergingthreats.net/t/pennywise-stealer-update-on-rules/812 "2023-07-28T22:14:15Z")

</div>

Pennywise stealer is still being used actively on YouTube malware campaigns but i cant find any ET rule detection although im aware some rules were written in the past. Maybe an update is needed to these new variants. S…

---

## [Hydrochasma (Fast Reverse Proxy)](https://community.emergingthreats.net/t/hydrochasma-fast-reverse-proxy/727)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 7\
**Last updated:** [July 27, 2023, 10:25pm UTC](https://community.emergingthreats.net/t/hydrochasma-fast-reverse-proxy/727 "2023-07-27T22:25:43Z")

</div>

Hi, community! We have fast reverse proxy traffic at our disposal. Rule: alert tcp any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] Hydrochasma Fast Reverse Proxy";flow: established, to\_server;dsize: 3; stream\_size: cl…

---

## [SIGNATURE: MalDoc/Gamaredon CnC: (ADMIN- prepend)](https://community.emergingthreats.net/t/signature-maldoc-gamaredon-cnc-admin-prepend/809)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 2\
**Last updated:** [July 27, 2023, 10:24pm UTC](https://community.emergingthreats.net/t/signature-maldoc-gamaredon-cnc-admin-prepend/809 "2023-07-27T22:24:56Z")

</div>

alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:“ET TROJAN MalDoc/Gamaredon CnC Activity”; flow:established,to\_server; content:“OPTIONS”; http\_method; content:“/ADMIN-”; http\_uri; depth:7; fast\_pattern; content:“Micros…

---

## [Lazarus APT Backdoor](https://community.emergingthreats.net/t/lazarus-apt-backdoor/785)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 5\
**Last updated:** [July 27, 2023, 8:32am UTC](https://community.emergingthreats.net/t/lazarus-apt-backdoor/785 "2023-07-27T08:32:29Z")

</div>

Hi! Lazarus is in touch, I found a sample in our sandbox and after an explanation from @h2jazi and @jaydinbas it turns out we are on the same vibe for which we thank them! Look at the rules: alert http any any -\> any …

---

## [Rockwell cve 2023-3595 and 2023-3596 signatures](https://community.emergingthreats.net/t/rockwell-cve-2023-3595-and-2023-3596-signatures/784)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 0\
**Last updated:** [July 20, 2023, 5:23pm UTC](https://community.emergingthreats.net/t/rockwell-cve-2023-3595-and-2023-3596-signatures/784 "2023-07-20T17:23:47Z")

</div>

Hey everyone, Long time, no post. I wanted to talk about a set of signatures that Rockwell and CISA collaborated on to provide coverage for CVE 2023-3595 and 2023-3596. Take a look at the CISA advisory here for more det…

---

## [Konni.APT](https://community.emergingthreats.net/t/konni-apt/765)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 1\
**Last updated:** [July 14, 2023, 9:00pm UTC](https://community.emergingthreats.net/t/konni-apt/765 "2023-07-14T21:00:14Z")

</div>

Hi, we have an Konni.APT here, I collected the links in my tweet : Let’s add a rule to this threat. I suggest the following two, but can probably come up with some more. alert http any any -\> any any (msg: "ET MALWARE…

---

## [Possible FP: ET MALWARE Sourtoff Receiving Simda Payload](https://community.emergingthreats.net/t/possible-fp-et-malware-sourtoff-receiving-simda-payload/736)

<div class="topic-metadata">

**Author:** [@bigjohns97](https://community.emergingthreats.net/u/bigjohns97)\
**Replies:** 4\
**Last updated:** [July 7, 2023, 11:21pm UTC](https://community.emergingthreats.net/t/possible-fp-et-malware-sourtoff-receiving-simda-payload/736 "2023-07-07T23:21:51Z")

</div>

Had this alert come up today and while there was a download of data there wasn’t any malicious malware detected (MS defender) so I am wondering if this md5 hash isn’t accurate? alert tcp $EXTERNAL\_NET 20000: → $HOME\_NET…

---

## [Mystic Stealer signature](https://community.emergingthreats.net/t/mystic-stealer-signature/658)

<div class="topic-metadata">

**Author:** [@dspruell](https://community.emergingthreats.net/u/dspruell)\
**Replies:** 6\
**Last updated:** [June 28, 2023, 11:00pm UTC](https://community.emergingthreats.net/t/mystic-stealer-signature/658 "2023-06-28T23:00:15Z")

</div>

Mystic Stealer C2 key exchange. alert tcp $HOME\_NET any -\> $EXTERNAL\_NET any (msg:"ET MALWARE Mystic Stealer C2 Client Hello Packet"; flow:established,to\_server; flowbits:set, mystic\_stealer\_conn\_init; flowbits:noalert;…

---

## [StatusRecorder](https://community.emergingthreats.net/t/statusrecorder/699)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 1\
**Last updated:** [June 27, 2023, 1:24pm UTC](https://community.emergingthreats.net/t/statusrecorder/699 "2023-06-27T13:24:05Z")

</div>

Hello! We thought for a while and discussed what we saw, and as a result I wrote the following rule: alert tcp any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] StatusRecorder";flow: established, to\_server; stream\_size: …

---

## [ObserverStealer](https://community.emergingthreats.net/t/observerstealer/624)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 5\
**Last updated:** [June 23, 2023, 3:37pm UTC](https://community.emergingthreats.net/t/observerstealer/624 "2023-06-23T15:37:00Z")

</div>

Hi all! A fairly new stealer was discovered today that leaves a note with an advertisement on the victim’s computer) This is very strange… I propose the following set of rules for detection: alert http any any -\> any an…

---

## [GoodMorning Ransomware](https://community.emergingthreats.net/t/goodmorning-ransomware/586)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 7\
**Last updated:** [June 23, 2023, 2:42pm UTC](https://community.emergingthreats.net/t/goodmorning-ransomware/586 "2023-06-23T14:42:13Z")

</div>

I would like to suggest you the rules from any.run. Is it okay if the name is their name? I just have them now. Link to sample: where it sends one GET request. Exfiltration was not found, perhaps it is in the encoded…

---

## [FPs on new sig 2854494](https://community.emergingthreats.net/t/fps-on-new-sig-2854494/677)

<div class="topic-metadata">

**Author:** [@kevin\_branch](https://community.emergingthreats.net/u/kevin_branch)\
**Replies:** 2\
**Last updated:** [June 20, 2023, 5:27pm UTC](https://community.emergingthreats.net/t/fps-on-new-sig-2854494/677 "2023-06-20T17:27:34Z")

</div>

2854494: ETPRO INFO Citrix/GotoMyPC Jedi Remote Control Session 2 - ICMP Traffic Immediately after this rule emerged across my NSM stacks, we started seeing FPs on it, all from Apple devices (both MacOS and iPhones). I…

---

## [SIG: MoveIt File Transfer WebShell Interaction](https://community.emergingthreats.net/t/sig-moveit-file-transfer-webshell-interaction/607)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 3\
**Last updated:** [June 13, 2023, 12:50pm UTC](https://community.emergingthreats.net/t/sig-moveit-file-transfer-webshell-interaction/607 "2023-06-13T12:50:17Z")

</div>

alert tcp $EXTERNAL\_NET any → $HOME\_NET $HTTP\_PORTS (msg:“MoveIt File Transfer WebShell Interaction X-siLock-Comment Header”; flow:established,to\_server; content:“X-siLock-Comment|3A|”; http\_header; fast\_pattern:only; cl…

---

## [DynamicRAT](https://community.emergingthreats.net/t/dynamicrat/634)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 2\
**Last updated:** [June 10, 2023, 12:15am UTC](https://community.emergingthreats.net/t/dynamicrat/634 "2023-06-10T00:15:01Z")

</div>

Hi guys! Today there is a joint report from @Gi7w0rm and @tosscoinwitcher I propose a rule for content from the client: alert tcp any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] DynamicRAT ";flow: established, to\_serv…

---

## [Gurcu stealer report outbound](https://community.emergingthreats.net/t/gurcu-stealer-report-outbound/589)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 7\
**Last updated:** [May 30, 2023, 1:24pm UTC](https://community.emergingthreats.net/t/gurcu-stealer-report-outbound/589 "2023-05-30T13:24:28Z")

</div>

Hi, I found that we do not detect some requests to send a report with metadata from the Gurcu stealer. Here I propose a rule for such activity. alert http any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] Gurcu Stealer Re…

---

## [New Signature: MalDoc/Gamaredon CnC Activity](https://community.emergingthreats.net/t/new-signature-maldoc-gamaredon-cnc-activity/575)

<div class="topic-metadata">

**Author:** [@kevross33](https://community.emergingthreats.net/u/kevross33)\
**Replies:** 1\
**Last updated:** [May 19, 2023, 10:45pm UTC](https://community.emergingthreats.net/t/new-signature-maldoc-gamaredon-cnc-activity/575 "2023-05-19T22:45:47Z")

</div>

alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:““MalDoc/Gamaredon CnC Activity”; flow:established,to\_server; content:“OPTIONS”; http\_method; content:”/USER-"; http\_uri; depth:6; fast\_pattern; content:“Microsoft Offic…

---

## [Tracemap checkin](https://community.emergingthreats.net/t/tracemap-checkin/569)

<div class="topic-metadata">

**Author:** [@NoahWolf](https://community.emergingthreats.net/u/NoahWolf)\
**Replies:** 2\
**Last updated:** [May 19, 2023, 11:42am UTC](https://community.emergingthreats.net/t/tracemap-checkin/569 "2023-05-19T11:42:35Z")

</div>

Found this malware on ANY.RUN. Here is the signature, alert http $HOME\_NET any -\> $EXTERNAL\_NET any (msg:"tracemap checkin"; http.method; content:"GET"; http.uri; content:"/api/traceman.php"; reference:url,https://app.a…

---

## [False positive for SID 2015813?: DNS Query Sinkhole Domain](https://community.emergingthreats.net/t/false-positive-for-sid-2015813-dns-query-sinkhole-domain/553)

<div class="topic-metadata">

**Author:** [@jimoe](https://community.emergingthreats.net/u/jimoe)\
**Replies:** 1\
**Last updated:** [May 15, 2023, 4:33pm UTC](https://community.emergingthreats.net/t/false-positive-for-sid-2015813-dns-query-sinkhole-domain/553 "2023-05-15T16:33:16Z")

</div>

I rather doubt that 8.8.8.8 is a dubious DNS server. 05/13/2023-22:26:21.656297 \[Drop\] \[\*\*\] \[1:2015813:8\] ET MALWARE DNS Query Sinkhole Domain Various Families (Possible Infected Host) \[\*\*\] \[Classification: Potentially…

---

## [Need a feedback about Kerio Control rule that's blocking the web, domen, even application](https://community.emergingthreats.net/t/need-a-feedback-about-kerio-control-rule-thats-blocking-the-web-domen-even-application/515)

<div class="topic-metadata">

**Author:** [@RasmusMAG](https://community.emergingthreats.net/u/RasmusMAG)\
**Replies:** 3\
**Last updated:** [May 1, 2023, 1:55pm UTC](https://community.emergingthreats.net/t/need-a-feedback-about-kerio-control-rule-thats-blocking-the-web-domen-even-application/515 "2023-05-01T13:55:16Z")

</div>

Can any one explain why I am getting this log when trying use zoom? All options are not working when I want to switch off this rule. Any idea? \[27/Apr/2023 23:57:28\] IPS: Packet drop, severity: Blacklist, Rule ID: 1:240…

---

## [Possible FP on 2044745 (SOMNIRECORD Backdoor CMD Command in DNS Query)?](https://community.emergingthreats.net/t/possible-fp-on-2044745-somnirecord-backdoor-cmd-command-in-dns-query/398)

<div class="topic-metadata">

**Author:** [@mflage](https://community.emergingthreats.net/u/mflage)\
**Replies:** 2\
**Last updated:** [March 23, 2023, 4:12pm UTC](https://community.emergingthreats.net/t/possible-fp-on-2044745-somnirecord-backdoor-cmd-command-in-dns-query/398 "2023-03-23T16:12:21Z")

</div>

Hi, I’m wondering if there’s a potential false positive on the 2044745 rule submitted yesterday. According to the write-up (Not sleeping anymore: SOMNIRECORD's wake-up call — Elastic Security Labs) this should look for …

---

## [2013914: Not really relevant anymore?](https://community.emergingthreats.net/t/2013914-not-really-relevant-anymore/350)

<div class="topic-metadata">

**Author:** [@netcrawlr](https://community.emergingthreats.net/u/netcrawlr)\
**Replies:** 1\
**Last updated:** [March 9, 2023, 2:21pm UTC](https://community.emergingthreats.net/t/2013914-not-really-relevant-anymore/350 "2023-03-09T14:21:52Z")

</div>

Hi team ET, found this gem while looking at signatures that is loaded but never fires: alert http $HOME\_NET any -\> $EXTERNAL\_NET any (msg:"ET POLICY APT User-Agent to BackTrack Repository"; flow:established,to\_server; …

---

## [GitLab Pre-Auth RCE (CVE-2021-22205) Signature](https://community.emergingthreats.net/t/gitlab-pre-auth-rce-cve-2021-22205-signature/308)

<div class="topic-metadata">

**Author:** [@cosmicgumbo](https://community.emergingthreats.net/u/cosmicgumbo)\
**Replies:** 3\
**Last updated:** [February 18, 2023, 12:30am UTC](https://community.emergingthreats.net/t/gitlab-pre-auth-rce-cve-2021-22205-signature/308 "2023-02-18T00:30:53Z")

</div>

As stated in the post, I don’t have a completed sig. I am not entirely sure how to sig on the injected code but I definitely think there is something here worth a sig. Let me know, thanks!

[Previous page](https://community.emergingthreats.net/c/rule-sigs/11.md?page=4)

[Next page](https://community.emergingthreats.net/c/rule-sigs/11.md?page=6)
