Category Archives: applications

HIDDEN COBRA – DDoS Botnet Infrastructure

Network Signatures alert tcp any any -> any any (msg:”DPRK_HIDDEN_COBRA_DDoS_HANDSHAKE_SUCCESS”; dsize:6; flow:established,to_server; content:”|18 17 e9 e9 e9 e9|”; fast_pattern:only; sid:1; rev:1;) ________________________________________________________________ alert tcp any any -> any any (msg:”DPRK_HIDDEN_COBRA_Botnet_C2_Host_Beacon”; flow:established,to_server; content:”|1b 17 e9 e9 e9 e9|”; depth:6; fast_pattern; sid:1; rev:1;) ________________________________________________________________ YARA Rules “strings: $rsaKey = {7B 4E 1E A7 E9 3F 36 4C […]

Also posted in security | Comments closed