""ET CURRENT_EVENTS WalletConnect Stealer Landing Page 2022-11-23""

SID: 2039837

Revision: 1

Class Type: trojan-activity

Metadata: attack_target Client_Endpoint, created_at 2022_11_23, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2022_11_23

Reference:

  • md5

  • f532aee5271714c6a3b5207adbf7a533

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "Open protocol for connecting Wallets to Dapps"

  • Value: "ethereum, cryptocurrency, wallet, mobile, connect, bridge, relay, proxy, standard, protocol, crypto, tokens, dapp"

  • Value: "@walletconnect"

  • Value: "ROBOTS AIDS"

  • Value: "wallet/css2"

  • Value: "|3c|title|3e|WalletConnect|3c 2f|title|3e|"

Within:

PCRE:

Special Options:

  • file_data

  • fast_pattern

source