SIGS: CastleLoader/RAT

Hi,

At the end of this recordedfuture report is snort rules for CastleLoader and CastleRAT

Thanks @kevross33 , @kraghu has been combing through this report for signature food!

@kevross33
2066299 - ET MALWARE CastleLoader Malware Outbound Checkin (malware.rules)
Has been released, more to come soon!

There are signatures at the end in the appendix.

1 Like
  • 2066349 - ET MALWARE CastleLoader Malware Outbound Payload Request (malware.rules)

  • 2066354 - ET MALWARE CastleLoader Malware Stager Outbound Payload Request (malware.rules)

  • 2066355 - ET MALWARE CastleLoader Malware Inbound Command Retrieval via Finger Service (malware.rules)

  • 2066356 - ET MALWARE CastleRAT Malware Outbound Handshake (malware.rules)

1 Like
  • 2066363 - ET MALWARE CastleRAT Malware Outbound Handshake M2 (malware.rules)

  • 2066364 - ET MALWARE CastleRAT Malware Outbound Handshake M3 (malware.rules)

  • 2066366 - ET MALWARE CastleRAT Malware Outbound Handshake M4 (malware.rules)

  • 2066367 - ET MALWARE CastleRAT Malware Outbound Handshake M5 (malware.rules)

  • 2066368 - ET MALWARE CastleRAT Malware Outbound Handshake M6 (malware.rules)

  • 2066369 - ET MALWARE CastleRAT Malware Outbound Handshake M7 (malware.rules)

  • 2066370 - ET MALWARE CastleRAT Malware Outbound Handshake M8 (malware.rules)

  • 2066371 - ET MALWARE CastleRAT Malware Outbound Handshake M9 (malware.rules)

1 Like