alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M1"; flow:established,to_server; content:"/counter/"; http_uri; fast_pattern:only; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:"MSIE 7.0"; http_header; pcre:"/\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; metadata: former_category TROJAN; classtype:trojan-activity; sid:2024035; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, deployment Perimeter, signature_severity Major, created_at 2017_03_08, updated_at 2017_03_17;)

Added 2017-08-07 21:19:19 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M1"; flow:established,to_server; content:"/counter/"; http_uri; fast_pattern:only; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:"MSIE 7.0"; http_header; pcre:"/\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; classtype:trojan-activity; sid:2024035; rev:3;)

Added 2017-05-05 16:58:57 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M1"; flow:established,to_server; content:"/counter/"; http_uri; fast_pattern:only; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:"MSIE 7.0"; http_header; pcre:"/\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; metadata: former_category TROJAN; classtype:trojan-activity; sid:2024035; rev:3;)

Added 2017-05-03 17:35:26 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M1"; flow:established,to_server; content:"/counter/"; http_uri; fast_pattern:only; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:"MSIE 7.0"; http_header; pcre:"/\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; classtype:trojan-activity; sid:2024035; rev:3;)

Added 2017-03-20 19:16:55 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M1"; flow:established,to_server; content:"/counter/"; http_uri; fast_pattern:only; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:"MSIE 7.0"; http_header; pcre:"/\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; classtype:trojan-activity; sid:2024035; rev:3;)

Added 2017-03-17 17:48:44 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M1"; flow:established,to_server; content:"/counter/?"; depth:10; http_uri; fast_pattern; pcre:"/^\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:"MSIE 7.0"; http_header; classtype:trojan-activity; sid:2024035; rev:2;)

Added 2017-03-08 18:54:41 UTC


Topic revision: r1 - 2017-08-08 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats