• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Possible Gorilla RAT C2 registration and TCP tunnel beacon traffic

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•2

    Detects outbound TCP traffic from the internal network to external destinations that match characteristics of Gorilla RAT registration beacons. This includes established sessions with small packet sizes (<64 bytes) and frequent, repeated attempts as defined by the threshold.

    Suricata

    Tags

    TA0011 - Command and ControlT1071 - Application Layer ProtocolNetwork Connection OutboundIDS IPS AlertNetwork GenericSnort IDSTCPTrojan Activity

    Found in

    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?