
Zeek 기반 AsyncRAT 악성코드 탐지기.
악성코드는 종종 HTTPS를 통해 명령 및 제어(C2) 서버와의 통신을 숨깁니다. HTTPS의 암호화는 일반적으로 악성코드가 목표를 달성할 때까지 감염 사실을 충분히 은폐합니다. 이로 인해 HTTPS를 사용하는 악성코드 탐지는 까다롭지만, 때때로 운 좋은 기회가 찾아오기도 합니다. 이번 AsyncRAT 사례가 그런 경우입니다. AsyncRAT은 지난 1년 동안 미국의 중요 인프라를 관리하는 조직을 대상으로 삼아 배포된 Windows 원격 액세스 도구입니다.
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2024-03-12-13-19-10
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1709051041.876652 CLNN1k2QMum1aexUK7 192.168.100.124 49207 181.131.218.39 4041 - - - tcp AsyncRAT::C2_Traffic_Observed Potential AsyncRAT C2 discovered via a default SSL certificate. Cert Fingerprints: [ce772ec37d88351f43e6350c6c2b9777c9a7855f2a55184fba784e5e7df9e3eb] Issuer: CN=AsyncRAT Server 192.168.100.124 181.131.218.39 4041 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2024-03-12-13-19-10
"suri" 디렉터리에서 Suricata 규칙을 찾을 수 있습니다.