# Possible FP: SID 2046267 ET MALWARE \[ANY.RUN\] RisePro TCP v.0.1 (External IP)

**URL:** https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655
**Category:** Feedback & Support
**Created:** [June 15, 2023, 7:04pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655 "2023-06-15T19:04:31Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![ksci](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@ksci](https://community.emergingthreats.net/u/ksci)
#### Post date: [June 15, 2023, 7:04pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/1 "2023-06-15T19:04:31Z")

</div>

I have multiple locations triggering the recently released rule ET MALWARE [ANY.RUN] RisePro TCP v.0.1 (External IP) for traffic going to what appears to be team viewer servers \*.router.teamviewer.com hosted by an IT service provider.

I assume this is a false positive and I cannot find any information about rise pro using teamviewer. I am unable to provide a pcap of the alerts triggering.

---

<div class="post-metadata">

### Author: ![trobinson667](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/trobinson667/32/544_2.png) [@trobinson667](https://community.emergingthreats.net/u/trobinson667)
#### Post date: [June 15, 2023, 10:17pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/2 "2023-06-15T22:17:08Z")

</div>

Hello there,

I’m sorry you’re experiencing issues with this rule. Would you mind answering a couple of questions to hopefully help me writing some modifications to the rule in order to reduce false positives?

- Is this traffic triggering specifically on teamviewer traffic?
- What destination ports are you seeing alerts trigger on?
- Are there any other destination hostnames/IP addresses in which the rule is triggering?

Thank you for your cooperation,

-Tony

---

<div class="post-metadata">

### Author: ![ksci](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@ksci](https://community.emergingthreats.net/u/ksci)
#### Post date: [June 15, 2023, 10:36pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/3 "2023-06-15T22:36:51Z")

</div>

So far it appears to have only triggered on Team viewer traffic

| Dest port | src port | Count |
| --- | --- | --- |
| 56582 | 5938 | 4 |
| 50435 | 443 | 2 |
| 62858 | 5938 | 2 |
| 12578 | 443 | 1 |
| 49192 | 443 | 1 |
| 49680 | 443 | 1 |
| 49733 | 443 | 1 |
| 50073 | 443 | 1 |
| 50135 | 443 | 1 |
| 50620 | 443 | 1 |
| 50638 | 443 | 1 |
| 50817 | 443 | 1 |
| 50990 | 443 | 1 |
| 51101 | 443 | 1 |
| 51334 | 443 | 1 |
| 51715 | 5938 | 1 |
| 52366 | 5938 | 1 |
| 52607 | 443 | 1 |
| 52778 | 443 | 1 |
| 53102 | 443 | 1 |
| 53373 | 443 | 1 |
| 53796 | 5938 | 1 |
| 54197 | 443 | 1 |
| 54588 | 443 | 1 |
| 54817 | 443 | 1 |

I performed lookups on the source IPs and all of the hostnames are \*.router.teamviewer.com

---

<div class="post-metadata">

### Author: ![trobinson667](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/trobinson667/32/544_2.png) [@trobinson667](https://community.emergingthreats.net/u/trobinson667)
#### Post date: [June 16, 2023, 5:26pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/4 "2023-06-16T17:26:14Z")

</div>

so for the time being, I’ve added some port negations to the RisePro TCP rules on ports 5938,443, and port 80 in order to prevent the rules from matching on traffic on those ports, which are teamviewer’s default (5938), and fallback ports (443, then port 80 as a last result) to remedy this problem for now. These fixes will be available in today’s standard daily rule release. Typically, the rule release is published by around 6-7pm EST. Once today’s rule release is out, please push it out to your sensors, and let us know whether or not our changes resolved this issue, or if the problems persist.

Thank you for reporting this issue, and your assistance.

-Tony

---

<div class="post-metadata">

### Author: ![ksci](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@ksci](https://community.emergingthreats.net/u/ksci)
#### Post date: [June 19, 2023, 5:45pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/5 "2023-06-19T17:45:19Z")

</div>

Thanks for doing this. we havent had this rule trigger since the update way deployed.

---

<div class="post-metadata">

### Author: ![Manav2038](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/manav2038/32/341_2.png) [@Manav2038](https://community.emergingthreats.net/u/Manav2038)
#### Post date: [July 2, 2023, 8:10am UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/6 "2023-07-02T08:10:34Z")

</div>

alert tcp $EXTERNAL\_NET ![80,443,5938] → $HOME\_NET any (msg:“ET MALWARE [ANY.RUN] RisePro TCP v.0.1 (External IP)”; flow:established,to\_client; dsize:19\<\>29; content:“|00 00 00 21 27 00 00|”; offset:5; depth:8; reference:md5,a1f3423e231abd59d45b2ec37f751bbc; reference:url,app.any.run/tasks/d4c145cc-6a2d-4512-9cd6-555f0f2e17ed; classtype:command-and-control; sid:2046267; rev:2; metadata:affected\_product Windows\_XP\_Vista\_7\_8\_10\_Server\_32\_64\_Bit, attack\_target Client\_Endpoint, created\_at 2023\_06\_14, deployment Perimeter, former\_category MALWARE, malware\_family RisePro, performance\_impact Low, confidence High, signature\_severity Major, updated\_at 2023\_06\_16; target:dest\_ip;)

alert tcp $HOME\_NET any → $EXTERNAL\_NET ![80,443,445,5938] (msg:“ET MALWARE [ANY.RUN] RisePro TCP v.0.1 (Exfiltration)”; flow:established,to\_server; dsize:\>1100; content:“|00 1F 27 00 00|”; offset:7; depth:5; reference:md5,a1f3423e231abd59d45b2ec37f751bbc; reference:url,app.any.run/tasks/d4c145cc-6a2d-4512-9cd6-555f0f2e17ed; classtype:command-and-control; sid:2046270; rev:3; metadata:affected\_product Windows\_XP\_Vista\_7\_8\_10\_Server\_32\_64\_Bit, attack\_target Client\_Endpoint, created\_at 2023\_06\_14, deployment Perimeter, former\_category MALWARE, malware\_family RisePro, performance\_impact Low, confidence High, signature\_severity Major, updated\_at 2023\_06\_23; target:src\_ip;)

These updated rules ain’t working for us after modifying it according to our requirements, it’s still triggering the alert making it spam our channel.

**Our modified rule based on the rule that you have provided** :

alert tcp $EXTERNAL\_NET any → $HOME\_NET ![5938,443,80] (msg:“Possible MALWARE [ANY.RUN] RisePro TCP v.0.1 (External IP)”; flow:established,to\_client; dsize:19\<\>29; content:!“.[teamviewer.com](http://teamviewer.com/)”;nocase; content:“|00 00 00 21 27 00 00|”; offset:5; depth:8; reference:md5,a1f3423e231abd59d45b2ec37f751bbc; reference:url,app.any.run/tasks/d4c145cc-6a2d-4512-9cd6-555f0f2e17ed; target:dest\_ip; priority:1; sid:2402175;)

It’s triggering for the port **5938** on the subdomains of **[teamviewer.com](http://teamviewer.com)** ([router9.teamviewer.com](http://router9.teamviewer.com), [router10.teamviewer.com](http://router10.teamviewer.com), [routerpool9.rlb.teamviewer.com](http://routerpool9.rlb.teamviewer.com), [routerpool10.rlb.teamviewer.com](http://routerpool10.rlb.teamviewer.com)) Can you please check our modified rule and suggest any changes if required as this rule ain’t working for us.

---

<div class="post-metadata">

### Author: ![trobinson667](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/trobinson667/32/544_2.png) [@trobinson667](https://community.emergingthreats.net/u/trobinson667)
#### Post date: [July 3, 2023, 1:55pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/7 "2023-07-03T13:55:45Z")

</div>

Hey, thank you for reporting this issue. However, this rule should not be triggering on port 5938/tcp at all due to the port negations defined in the header for both rules that seem to be giving you problems. Based on what I can see, I know you have the latest version of the these rules downloaded of course, but has the Suricata daemon (or daemons, plural if your sensor runs multiple, concurrently) been restarted recently? Suricata will not load any newly downloaded or locally created rules until the service has been restarted. I suspect this is what is going on here.

Can you please try restarting the Suricata daemon(s)/service(s) on your sensor, and tell me if the problem persists? and if it does, can you provide us a copy of the eve.json output from the alerts triggering?

Again, thank you very much for your time, I hope this helps

-Tony R

---

<div class="post-metadata">

### Author: ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)
#### Post date: [July 11, 2023, 11:05am UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/8 "2023-07-11T11:05:41Z")

</div>

> [@ksci](#):
>
> ET MALWARE [ANY.RUN] RisePro TCP v.0.1 (External IP)

Adding these keywords will significantly reduce the number of FP

stream\_size: client, \<, 100;  
stream\_size: server, \<, 100;

---

<div class="post-metadata">

### Author: ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)
#### Post date: [July 11, 2023, 11:15am UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/9 "2023-07-11T11:15:52Z")

</div>

> [@Manav2038](#):
>
> ET MALWARE [ANY.RUN] RisePro TCP v.0.1 (Exfiltration)

To date, I have examined 47 samples and can offer a less proactive rule, using the magic constant

```auto
alert tcp $HOME_NET any -> $EXTERNAL_NET ![80,443,445,5938] (msg:"ET MALWARE [ANY.RUN] RisePro TCP v.0.1 (Exfiltration)"; 
flow:established,to_server; 
dsize:>1100; 
content: "|AD DA BA AB|"; depth:4; 
content:"|00 1F 27 00 00|"; offset:7; depth:5; 
reference:md5,a1f3423e231abd59d45b2ec37f751bbc; 
reference:url,app.any.run/tasks/d4c145cc-6a2d-4512-9cd6-555f0f2e17ed; 
classtype:command-and-control; sid:2046270; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2023_06_14, deployment Perimeter, former_category MALWARE, malware_family RisePro, performance_impact Low, confidence High, signature_severity Major, updated_at 2023_06_23; target:src_ip;)

alert tcp $HOME_NET any -> $EXTERNAL_NET ![80,443,5938] (msg:"ET MALWARE [ANY.RUN] RisePro TCP v.0.1 (Activity)"; 
flow:established,to_server; 
dsize:12; 
content: "|AD DA BA AB|"; depth:4; 
content:"|00 00 00 00 10 27 00 00|"; offset:4; depth:8; 
reference:md5,a1f3423e231abd59d45b2ec37f751bbc; 
reference:url,app.any.run/tasks/d4c145cc-6a2d-4512-9cd6-555f0f2e17ed; 
classtype:command-and-control; sid:2046269; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2023_06_14, deployment Perimeter, former_category MALWARE, malware_family RisePro, performance_impact Low, confidence High, signature_severity Major, updated_at 2023_06_16; target:src_ip;)

```

---

<div class="post-metadata">

### Author: ![Manav2038](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/manav2038/32/341_2.png) [@Manav2038](https://community.emergingthreats.net/u/Manav2038)
#### Post date: [July 12, 2023, 12:48pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/10 "2023-07-12T12:48:47Z")

</div>

Thanks, could you please explain me the content fields in detail:

content: “|AD DA BA AB|”; depth:4;  
content:“|00 1F 27 00 00|”; offset:7; depth:5;

---

<div class="post-metadata">

### Author: ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)
#### Post date: [July 12, 2023, 1:42pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/11 "2023-07-12T13:42:23Z")

</div>

ADDA BAAB - magic constant  
00 1f 27 00 00 - command

---

<div class="post-metadata">

### Author: ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)
#### Post date: [July 13, 2023, 3:12pm UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/12 "2023-07-13T15:12:08Z")

</div>

Magic bytes serve as an indicator that the connection is initiated by the client and not by the browser, for example.  
1f 27 - command  
there are 4 bytes of data length in front of them, but since they are less than 16 megabytes, the fourth byte is zero.

---

<div class="post-metadata">

### Author: ![samjenk](https://avatars.discourse-cdn.com/v4/letter/s/85e7bf/32.png) [@samjenk](https://community.emergingthreats.net/u/samjenk)
#### Post date: [July 14, 2023, 11:59am UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/13 "2023-07-14T11:59:39Z")

</div>

This discussion is a perfect example of why I joined this community. Thanks for taking the time to ask questions, @ksci, and propose solutions @trobinson667, @Manav2038 and @Jane0sint!

---

<div class="post-metadata">

### Author: ![Manav2038](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/manav2038/32/341_2.png) [@Manav2038](https://community.emergingthreats.net/u/Manav2038)
#### Post date: [July 16, 2023, 10:50am UTC](https://community.emergingthreats.net/t/possible-fp-sid-2046267-et-malware-any-run-risepro-tcp-v-0-1-external-ip/655/14 "2023-07-16T10:50:32Z")

</div>

Thanks!!
