Back to Rule

Rule History

SID: 2001452 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 9Jul 30, 2010, 12:00 PM

ET ADWARE_PUP Bundleware Spyware CHM Download

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP Bundleware Spyware CHM Download"; flow: to_server,established; content:"Referer|3a| ms-its|3a|mhtml|3a|file|3a|//C|3a|counter.mht!http|3a|//"; nocase; content:"/counter/HELP3.CHM|3a 3a|/help.htm"; nocase; classtype:pup-activity; sid:2001452; rev:9; metadata:created_at 2010_07_30, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_08_14;)

Jul 30, 2010, 12:00 PM

Aug 14, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 14, 2025, 9:34 PM

rules/emerging-adware_pup.rules