29 lines
999 B
YAML
29 lines
999 B
YAML
id: brute-ratel-c4
|
|
|
|
info:
|
|
name: Brute Ratel C4 - Detect
|
|
author: pussycat0x
|
|
severity: info
|
|
description: |
|
|
Brute Ratel C4 (BRc4) is a legit red-teaming tool designed from the ground up with evasion capabilities in mind, but in the wrong hands can cause significant damage. Learn how to protect your organization with our Brute Ratel C4 Spotlight.
|
|
reference:
|
|
- https://bruteratel.com/
|
|
metadata:
|
|
verified: "true"
|
|
max-request: 1
|
|
shodan-query: http.html_hash:-1957161625
|
|
tags: c2,bruteratel,c4,panel
|
|
|
|
http:
|
|
- method: GET
|
|
path:
|
|
- "{{BaseURL}}"
|
|
|
|
matchers-condition: and
|
|
matchers:
|
|
- type: dsl
|
|
dsl:
|
|
- "contains(body, '404 file not found')"
|
|
- "(\"1a279f5df4103743b823ec2a6a08436fdf63fe30\" == sha1(body))"
|
|
condition: and
|
|
# digest: 4a0a00473045022100cd5cd2330b7e2d4096dbe45a8b705242bfb468b852259e14afc4d7068a444f150220237c96a8d367ae034fc8fd5e37492345eab15c7f3366a51e019a768450c75acc:922c64590222798bb761d5b6d8e72950 |