
QuasarRat用のZeek検出器
マルウェアは、コマンド&コントロール(C2)サーバーとの通信をHTTPS上に隠すことがよくあります。HTTPSの暗号化により、マルウェアがその目的を達成するのに十分な間、侵害が隠蔽されるのが通常です。このため、HTTPSを使用するマルウェアの検出は困難ですが、今回のQuasarRATのように、たまに幸運が訪れることがあります。QuasarRATはWindowsリモートアクセスツールで、過去1年間にわたって米国の重要インフラを管理する組織を標的に展開されてきました。
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2024-10-09-18-06-57
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1723831638.402474 CpKJJiDUPEBNMGSC 192.168.100.7 49744 86.136.67.231 1337 - - - tcp QuasarRAT::C2_Traffic_Observed_Cert Potential QuasarRAT C2 - default SSL certificate discovered. - 192.168.100.7 86.136.67.231 1337 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2024-10-09-18-06-57
Suricataルールは"suri"ディレクトリにあります。