alert tcp $HOME_NET any → $EXTERNAL_NET $HTTP_PORTS (msg:“ET TROJAN TinyTurlaNG Turla APT Initial Client Beacon”; flow:established,to_server; content:“POST”; http_method; content:"form-data|3B|name=|22|id|22|; http_client_body; content:“form-data|3B|name=|22|result|22|”; http_client_body; distance:0; content:“Client Ready”; http_client_body; distance:0; classtype:trojan-activity; reference:url,blog.talosintelligence.com/tinyturla-next-generation/; sid:123441; rev:1;)
alert tcp $HOME_NET any → $EXTERNAL_NET $HTTP_PORTS (msg:“ET TROJAN TinyTurlaNG Turla APT GetTask Request”; flow:established,to_server; content:“POST”; http_method; content:"form-data|3B|name=|22|id|22|; http_client_body; content:“form-data|3B|name=|22|gettask|22|”; http_client_body; fast_pattern:4,20; distance:0; classtype:trojan-activity; reference:url,blog.talosintelligence.com/tinyturla-next-generation/; sid:123442; rev:1;)
Kind Regards,
Kevin Ross