""ET TROJAN SiameseKitten/Lyceum/Hexane MSIL/Shark Uploading to CnC""

SID: 2033762

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2021_08_22, malware_family Shark, updated_at 2021_08_22

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "?q="

  • Value: "o543n"

  • Value: "|28|Windows|20|NT|20|10.0|3b 20|Win64|3b 20|x64|29|"

  • Value: "|7b 22|Data|22 3a 5b 22|" Depth: 10

  • Value: "|22 5d 7d|"

Within:

PCRE: "/^\x7b\x22Data\x22\x3a\x5b\x22(?:[A-Z0-9+/]{4})*(?:[A-Z0-9+/]{2}==|[A-Z0-9+/]{3}=|[A-Z0-9+/]{4})/P"

Special Options:

  • http_method

  • http_uri

  • http_uri

  • fast_pattern

  • http_header

  • http_client_body

  • http_client_body

source