ET-3314
📛 Threat Title
SIG: EarthWorm Reverse SOCKS Handshake and Tunnel Sequence Detection
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- SIG: EarthWorm Reverse SOCKS Handshake and Tunnel Sequence Detection Emerging Threats Community
Remediations (8)
-
web:attack.mitre.org
MITRE ATT&CK ® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community. With the creation of ATT&CK, MITRE is fulfilling its mission ...
-
web:community.emergingthreats.net
The Pygmy Goat report documents an EarthWorm related implementation in which a pool number is assigned during the handshake sequence . In that protocol mapping, the handshake and tunnel records are still six bytes long, but the later bytes can carry a pool-specific value.
-
web:elastic.github.io
Identifies the execution of the EarthWorm tunneler. Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection and network filtering, or to enable access to otherwise unreachable systems.
-
web:github.com
EarthWorm Reverse SOCKS PCAP Lab Local-only Docker lab for generating EarthWorm reverse SOCKS PCAPs with a browser UI.
-
web:github.com
EarthWorm Reverse SOCKS PCAP Lab Local-only Docker lab for generating EarthWorm reverse SOCKS PCAPs with a browser UI.
-
web:github.com
Welcome to the Sigma main rule repository. The place where detection engineers, threat hunters and all defensive security practitioners collaborate on detection rules. The repository offers more than 3000 detection rules of different type and aims to make reliable detections accessible to all at no cost. Currently the repository offers three types of rules: Generic Detection Rules - Are threat ...
-
web:www.elastic.co
Triage and analysis Investigating Potential Protocol Tunneling via EarthWorm Attackers can leverage earthworm to clandestinely tunnel network communications and evade security measures, potentially gaining unauthorized access to sensitive systems. This rule looks for several command line arguments that are consistent with earthworm tunneling ...
-
web:www.snort.org
This rule may alert on any of the subcommands involved in the client-server handshake of custom TCP protocol used by Earthworm , including the establishment of a reverse socks5 tunnel from the server to the client. What To Look For This rule alerts on network communications from the Earthworm network proxy tool.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.