alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO SUSPICIOUS .scr file download"; flow:established,to_server; content:".scr"; http_uri; isdataat:!1,relative; fast_pattern; content:!"kaspersky.com"; http_host; metadata: former_category INFO; classtype:trojan-activity; sid:2018231; rev:5; metadata:created_at 2014_03_07, updated_at 2019_09_28;)

Added 2019-10-09 19:08:52 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO SUSPICIOUS .scr file download"; flow:established,to_server; content:".scr"; http_uri; isdataat:!1,relative; fast_pattern; content:!"kaspersky.com"; http_host; classtype:trojan-activity; sid:2018231; rev:5; metadata:created_at 2014_03_07, updated_at 2019_09_28;)

Added 2019-10-01 08:28:08 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO SUSPICIOUS .scr file download"; flow:established,to_server; content:".scr"; http_uri; isdataat:!1,relative; fast_pattern; content:!"kaspersky.com"; http_host; classtype:trojan-activity; sid:2018231; rev:5; metadata:created_at 2014_03_07, updated_at 2019_09_28;)

Added 2019-10-01 04:22:31 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO SUSPICIOUS .scr file download"; flow:established,to_server; content:".scr"; http_uri; isdataat:!1,relative; fast_pattern; content:!"kaspersky.com"; http_host; classtype:trojan-activity; sid:2018231; rev:5; metadata:created_at 2014_03_07, updated_at 2016_08_25;)

Added 2018-09-13 19:48:32 UTC


Added 2018-09-13 17:58:30 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO SUSPICIOUS .scr file download"; flow:established,to_server; content:".scr"; http_uri; fast_pattern:only; pcre:"/\x2Escr$/U"; content:!"kaspersky.com|0d 0a|"; http_header; classtype:trojan-activity; sid:2018231; rev:4; metadata:created_at 2014_03_07, updated_at 2016_08_25;)

Added 2017-08-07 21:12:17 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO SUSPICIOUS .scr file download"; flow:established,to_server; content:".scr"; http_uri; fast_pattern:only; pcre:"/\x2Escr$/U"; content:!"kaspersky.com|0d 0a|"; http_header; classtype:trojan-activity; sid:2018231; rev:4;)

Added 2016-08-26 17:31:54 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET INFO SUSPICIOUS .scr file download"; flow:established,to_server; content:".scr"; http_uri; fast_pattern:only; pcre:"/\x2Escr$/U"; classtype:trojan-activity; sid:2018231; rev:2;)

Added 2014-03-07 19:27:58 UTC


Topic revision: r1 - 2019-10-09 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats