Network Signatures alert tcp any any -> any any (msg:”DPRK_HIDDEN_COBRA_DDoS_HANDSHAKE_SUCCESS”; dsize:6; flow:established,to_server; content:”|18 17 e9 e9 e9 e9|”; fast_pattern:only; sid:1; rev:1;) ________________________________________________________________ alert tcp any any -> any any (msg:”DPRK_HIDDEN_COBRA_Botnet_C2_Host_Beacon”; flow:established,to_server; content:”|1b 17 e9 e9 e9 e9|”; depth:6; fast_pattern; sid:1; rev:1;) ________________________________________________________________ YARA Rules “strings: $rsaKey = {7B 4E 1E A7 E9 3F 36 4C […]
-
Recent Posts
- JSON ContentTypeHandler
- Mac OS X vulnerability – execution of arbitrary Javascript code without restrictions
- Snort rules for Petya ransomware
- HIDDEN COBRA – DDoS Botnet Infrastructure
- Unauthenticated buffer overflow exploit
- Python – exploit script
- Bind mounts
- Autodafé
- Sulley request designed to fuzz a Web server
- General Purpose Fuzzer (GPF)
Tags
Contact
rniko@cryptolab.net
License