Skip to content

TVRat / TeamSpy C2 Traffic #8

Description

@recvfrom

Overview
Write Snort rules for the command and control (C2) traffic used by TVRat (a remote access trojan leveraging the legitimate TeamViewer application)

Proposal
Write Snort rules (likely two) for Predator the Thief C2 traffic. For more info, see:

Expected Difficulty
Beginner/Easy - The C2 protocol is very basic, write-ups exist that detail the purpose of the protocol data, etc.

Technical Info
https://app.any.run/tasks/686989ed-f442-4463-afe5-2b547bf17485/
https://app.any.run/tasks/859c1d99-72d7-4d5e-a9fb-5ad157fa73b4/
tvrat-pcaps.zip (password: infected)

Metadata

Metadata

Assignees

No one assigned

    Labels

    BeginnerThis project is good for beginnersSnortSignifies a Snort Rule Project

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions