
Zeek ベースの AsyncRAT マルウェア検出器。
マルウェアは、そのコマンド&コントロール(C2)サーバーとの通信をHTTPS上に隠すことがよくあります。 HTTPSの暗号化により、マルウェアは通常、その目的を達成するのに十分な期間、侵害を隠蔽します。そのため、HTTPSを使用するマルウェアの検出は困難ですが、今回のAsyncRATのように、時には幸運な突破口が得られることもあります。AsyncRATは、過去1年間に米国の重要インフラを管理する組織を標的として展開されてきたWindowsリモートアクセスツールです。
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2024-03-12-13-19-10
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1709051041.876652 CLNN1k2QMum1aexUK7 192.168.100.124 49207 181.131.218.39 4041 - - - tcp AsyncRAT::C2_Traffic_Observed Potential AsyncRAT C2 discovered via a default SSL certificate. Cert Fingerprints: [ce772ec37d88351f43e6350c6c2b9777c9a7855f2a55184fba784e5e7df9e3eb] Issuer: CN=AsyncRAT Server 192.168.100.124 181.131.218.39 4041 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2024-03-12-13-19-10
Suricata ルールは "suri" ディレクトリにあります。