恶意软件经常通过 HTTPS 隐藏其与命令与控制(C2)服务器的通信。HTTPS 中的加密通常会掩盖入侵行为,使恶意软件得以完成其目标。这使得检测使用 HTTPS 的恶意软件颇具挑战性,但偶尔你也会碰到好运,就像这里的 AsyncRAT 案例一样——AsyncRAT 是一款 Windows 远程访问工具,在过去一年中被用于攻击美国管理关键基础设施的组织。
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2024-03-12-13-19-10
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1709051041.876652 CLNN1k2QMum1aexUK7 192.168.100.124 49207 181.131.218.39 4041 - - - tcp AsyncRAT::C2_Traffic_Observed Potential AsyncRAT C2 discovered via a default SSL certificate. Cert Fingerprints: [ce772ec37d88351f43e6350c6c2b9777c9a7855f2a55184fba784e5e7df9e3eb] Issuer: CN=AsyncRAT Server 192.168.100.124 181.131.218.39 4041 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2024-03-12-13-19-10
您可以在“suri”目录中找到 Suricata 规则。