Signature: CleanUp Loader

More info here This request is made over HTTPS so requires decryption to see.

alert tcp $HOME_NET any → EXTERNAL_NET $HTTP_PORTS (msg:“ET MALWARE CleanUp Loader Request”; flow:established,to_server; content:“POST”; http_method; content:“/api/”; http_uri; depth:5; content:“User-Agent|3A| HTTPGET”; http_header; pcre:“/^/api/(connectivity|session|connect)$/U”; classtype:trojan-activity; reference:url,; sid:134001; rev:1;)

Kind Regards,
Kevin Ross


Hey @kevross33!

Thanks for the tip, we’ll get this in today’s release!


@kevross33 - Here’s the sid for the rule that went out today.

2056580 - ET MALWARE CleanUp Loader HTTP Request (GET)