alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET TROJAN Dridex Base64 Executable"; flow:from_server,established; content:"200"; http_stat_code; content:"|47 4f 44 5a 49 4c 4c 41|"; http_cookie; file_data; content:"

[a-z])\x22\sname=\x22(?P=id)\x22>TVqQAA/Rsi"; classtype:trojan-activity; sid:2022595; rev:2; metadata:created_at 2016_03_05, updated_at 2020_06_24;)

Added 2021-09-21 20:00:33 UTC


alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET TROJAN Dridex Base64 Executable"; flow:from_server,established; content:"200"; http_stat_code; content:"|47 4f 44 5a 49 4c 4c 41|"; http_cookie; file_data; content:"

[a-z])\x22\sname=\x22(?P=id)\x22>TVqQAA/Rsi"; classtype:trojan-activity; sid:2022595; rev:2; metadata:created_at 2016_03_04, updated_at 2020_06_24;)

Added 2020-06-24 19:08:31 UTC


alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET TROJAN Dridex Base64 Executable"; flow:from_server,established; content:"200"; http_stat_code; content:"|47 4f 44 5a 49 4c 4c 41|"; http_cookie; file_data; content:"

[a-z])\x22\sname=\x22(?P=id)\x22>TVqQAA/Rsi"; classtype:trojan-activity; sid:2022595; rev:2; metadata:created_at 2016_03_04, updated_at 2016_03_04;)

Added 2018-09-13 19:52:22 UTC


Added 2018-09-13 18:00:47 UTC


alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET TROJAN Dridex Base64 Executable"; flow:from_server,established; content:"200"; http_stat_code; content:"|47 4f 44 5a 49 4c 4c 41|"; http_cookie; file_data; content:"

[a-z])\x22\sname=\x22(?P=id)\x22>TVqQAA/Rsi"; classtype:trojan-activity; sid:2022595; rev:2; metadata:created_at 2016_03_04, updated_at 2016_03_04;)

Added 2017-08-07 21:17:32 UTC


alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET TROJAN Dridex Base64 Executable"; flow:from_server,established; content:"200"; http_stat_code; content:"|47 4f 44 5a 49 4c 4c 41|"; http_cookie; file_data; content:"

[a-z])\x22\sname=\x22(?P=id)\x22>TVqQAA/Rsi"; classtype:trojan-activity; sid:2022595; rev:2;)

Added 2016-03-04 17:32:20 UTC


Topic revision: r1 - 2021-09-22 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats