#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET DELETED CoolEK? - Landing Page (2)"; flow:established,to_client; file_data; content:"|0D 0A|"; classtype:trojan-activity; sid:2016066; rev:3; metadata:created_at 2012_12_19, former_category EXPLOIT_KIT, updated_at 2021_06_23;)

Added 2021-06-23 19:31:49 UTC


#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET DELETED CoolEK? - Landing Page (2)"; flow:established,to_client; file_data; content:"|0D 0A|"; classtype:trojan-activity; sid:2016066; rev:3; metadata:created_at 2012_12_19, former_category EXPLOIT_KIT, updated_at 2012_12_19;)

Added 2020-08-05 19:08:40 UTC


#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET DELETED CoolEK? - Landing Page (2)"; flow:established,to_client; file_data; content:"|0D 0A|"; metadata: former_category EXPLOIT_KIT; classtype:trojan-activity; sid:2016066; rev:3; metadata:created_at 2012_12_19, updated_at 2012_12_19;)

Added 2019-09-26 19:57:16 UTC


#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET DELETED CoolEK? - Landing Page (2)"; flow:established,to_client; file_data; content:"|0D 0A|"; classtype:trojan-activity; sid:2016066; rev:3; metadata:created_at 2012_12_19, updated_at 2012_12_19;)

Added 2018-09-13 19:46:01 UTC


Added 2018-09-13 17:57:08 UTC


#alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET DELETED CoolEK? - Landing Page (2)"; flow:established,to_client; file_data; content:"|0D 0A|"; classtype:trojan-activity; sid:2016066; rev:3; metadata:created_at 2012_12_19, updated_at 2012_12_19;)

Added 2017-08-07 21:09:43 UTC


##alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET DELETED CoolEK? - Landing Page (2)"; flow:established,to_client; file_data; content:"|0D 0A|"; classtype:trojan-activity; sid:2016066; rev:2;)

Added 2013-08-02 21:19:10 UTC


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET CURRENT_EVENTS CoolEK? - Landing Page (2)"; flow:established,to_client; file_data; content:"|0D 0A|"; classtype:trojan-activity; sid:2016066; rev:1;)

Added 2012-12-19 20:55:39 UTC


Topic revision: r1 - 2021-06-23 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats