""ET TROJAN Possible W4SP Stealer CnC Checkin""

SID: 2049793

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Linux, attack_target Linux_Unix, created_at 2023_12_19, deployment Perimeter, malware_family W4SP_Stealer, performance_impact Low, confidence High, signature_severity Major, updated_at 2023_12_19

Reference:

  • md5

  • 686f6d2fb8dd540052f2c698e8aff662

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|7b 22|hostname|22 3a 22|" Depth: 13

  • Value: "|22 2c 22|macAddress|22 3a 22|"

  • Value: "|22 2c 22|username|22 3a 22|"

Within:

PCRE: "/^([a-f0-9]{2}\:){5}[a-f0-9]{2}/R"

Special Options:

  • fast_pattern

source