# RedLine Stealer beacon

**URL:** <https://community.emergingthreats.net/t/redline-stealer-beacon/250>\
**Category:** Rule Signatures\
**Created:** [January 6, 2023, 1:59pm UTC](https://community.emergingthreats.net/t/redline-stealer-beacon/250 "2023-01-06T13:59:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![NoahWolf](https://avatars.discourse-cdn.com/v4/letter/n/a6a055/32.png) [@NoahWolf](https://community.emergingthreats.net/u/NoahWolf)\
**Post date:** [January 6, 2023, 1:59pm UTC](https://community.emergingthreats.net/t/redline-stealer-beacon/250/1 "2023-01-06T13:59:04Z")

</div>

I found this malware on Any.Run.

```auto
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"RedLine Stealer beacon"; content:"Authorization"; content:"net|2e|tcp://"; pcre:"/[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}:[0-9]{1,5}/"; pcre:"/[0-9a-f]{32}/"; reference:url,https://app.any.run/tasks/8c84dec3-b855-4e26-bdd2-639ce1de731e/; sid:2008004; rev:1;)

```

---

<div class="post-metadata">

**Author:** ![trobinson667](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/trobinson667/32/544_2.png) [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Post date:** [January 6, 2023, 6:54pm UTC](https://community.emergingthreats.net/t/redline-stealer-beacon/250/2 "2023-01-06T18:54:58Z")

</div>

Hey Noah,

Thank you for submitting this rule to us, however I have a bit of good news and bad news:

The good news is that we already have coverage for the traffic  
bad news is that currently its in the ETPRO ruleset.

We had three rules that fired on this sample:

```auto
2850027 TCP CnC net.tcp Init
2850286 TCP CnC Activity
2850353 TCP CnC - Id1Response

```

The good news is, we will be moving all three of these rules from ETPRO to the ETOPEN ruleset effective TODAY.  
So the bad news is, we won’t be implementing this rule into the ETOPEN ruleset, but all ETOPEN users will now be able to benefit from the existing rules that were in the ETPRO ruleset.

Thank you again for sharing your findings, and please have a nice weekend.
