Skip to content

PonyStealer Exfil Attempts #7

Description

@recvfrom

Overview
Write Snort rules for traffic related to PonyStealer (commodity infostealer malware) exfiltrating collecting data

Proposal
Write Snort rules for PonyStealer exfil traffic. For more info, see:

Expected Difficulty

  • Beginner/Easy - The C2 protocol is very basic, write-ups exist that detail the purpose of the protocol data, etc.

Technical Info
ponystealer-pcap.zip (password: infected)

Metadata

Metadata

Assignees

No one assigned

    Labels

    BeginnerThis project is good for beginnersSnortSignifies a Snort Rule Project

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions