# WhiteSnake

**URL:** <https://community.emergingthreats.net/t/whitesnake/1338>\
**Category:** Rule Signatures\
**Created:** [January 30, 2024, 6:56am UTC](https://community.emergingthreats.net/t/whitesnake/1338 "2024-01-30T06:56:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [January 30, 2024, 6:56am UTC](https://community.emergingthreats.net/t/whitesnake/1338/1 "2024-01-30T06:56:29Z")

</div>

Hi, I noticed that Whitesnake has changed the protocol a little, let’s write the rules!

> **[Analysis 94048358360fd46766cdf1d4f487c1c61a391f97ebc10704c388170ae4e66b88.exe...](https://app.any.run/tasks/5dc1cfaa-5470-4708-92d8-b8703b47c1f7/)**
>
> Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/3c41e86529b7116262dc936d1076f3097816f6bd.png)  
 ![image](https://us1.discourse-cdn.com/flex016/uploads/emergingthreats/original/1X/7787089cfcca314e109cf8221ac1ec1f3f6e70f6.png)

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] WhiteSnake Stealer HTTP Request";
flow: established, to_server; http.method;
content: "POST"; 
http.uri;
content: "/sendData?pk=";
content: "&ta="; distance: 0;
content: "&un="; distance: 0;
content: "&pc="; distance: 0;
content: "&co="; distance: 0;
content: "&wa="; distance: 0;
content: "&be="; distance: 0; 
http.header_names;
content: "|0d 0a|Host|0d 0a|Content-Length|0d 0a|Expect|0d 0a|Connection|0d 0a 0d 0a|";startswith;
reference: md5,5302fff6311dab7554eaf7902c2aaa61;
reference: url,app.any.run/tasks/5dc1cfaa-5470-4708-92d8-b8703b47c1f7;
metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family WhiteSnake, tag stealer, created_at 2024_01_29; classtype: trojan-activity;
sid: 1; rev: 1;)

```

```auto
alert http any any -> any any (msg: "ET MALWARE [ANY.RUN] WhiteSnake Stealer HTTP POST Report Exfiltration";
flow: established, to_server; http.method;
content: "POST"; http.header_names;
content: "|0d 0a|Host|0d 0a|Content-Length|0d 0a|Expect|0d 0a|Connection|0d 0a 0d 0a|"; startswith;
http.request_body;
content: "WSR$"; depth: 4;
reference: md5,5302fff6311dab7554eaf7902c2aaa61;
reference: url,app.any.run/tasks/5dc1cfaa-5470-4708-92d8-b8703b47c1f7;
metadata: attack_target Client_Endpoint, deployment Perimeter, former_category MALWARE, signature_severity Major, malware_family WhiteSnake, tag stealer, created_at 2024_01_29; classtype: trojan-activity;
sid: 2; rev: 1;)

```

𖡼𖤣𖥧𖡼𓋼𖤣𖥧𓋼𓍊 Jane

---

<div class="post-metadata">

**Author:** ![bingohotdog](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/bingohotdog/32/42_2.png) [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Post date:** [January 30, 2024, 7:49pm UTC](https://community.emergingthreats.net/t/whitesnake/1338/2 "2024-01-30T19:49:07Z")

</div>

Nice catch, Jane! Adding these soon 🤖…

🌭

---

<div class="post-metadata">

**Author:** ![bingohotdog](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/bingohotdog/32/42_2.png) [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Post date:** [January 31, 2024, 6:00pm UTC](https://community.emergingthreats.net/t/whitesnake/1338/3 "2024-01-31T18:00:44Z")

</div>

Yesterday’s released contained these rules:  
2050601 - ET MALWARE [ANY.RUN] WhiteSnake Stealer HTTP Request (malware.rules)  
2050602 - ET MALWARE [ANY.RUN] WhiteSnake Stealer HTTP POST Report Exfiltration (malware.rules)

Thanks again, Jane. The team always appreciates your contributions.

---

<div class="post-metadata">

**Author:** ![Jane0sint](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/jane0sint/32/398_2.png) [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Post date:** [June 17, 2024, 10:22am UTC](https://community.emergingthreats.net/t/whitesnake/1338/4 "2024-06-17T10:22:46Z")

</div>

Hello, I would like to ask you to replace the link in the reference with this  
`community.emergingthreats.net/t/whitesnake/`  
𖡼𖤣𖥧𖡼𓋼𖤣𖥧𓋼𓍊 Jane

---

<div class="post-metadata">

**Author:** ![bingohotdog](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/bingohotdog/32/42_2.png) [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Post date:** [June 17, 2024, 6:23pm UTC](https://community.emergingthreats.net/t/whitesnake/1338/5 "2024-06-17T18:23:16Z")

</div>

Howdy, Jane! Will do. 🤠
