Back to Rule

Rule History

SID: 2013045 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 3Jun 16, 2011, 12:00 PM

ET MALWARE DLoader File Download Request Activity

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE DLoader File Download Request Activity"; flow:established,to_server; http.uri; content:"/load.php?file="; pcre:"/^(?:\d+|(?:\w+)?grabbers?|uploader)(?:&luck=\d)?$/R"; reference:md5,12554e7f2e78daf26e73a2f92d01e7a7; reference:url,about-threats.trendmicro.com/malware.aspx?language=us&name=TROJ_VBKRYPT.CB; reference:md5,3310259795b787210dd6825e7b6d6d28; reference:url,www.f-secure.com/v-descs/trojan-downloader_w32_kdv176347.shtml; reference:md5,7af2097d75869aa5aa656cd6e523c8b3; classtype:trojan-activity; sid:2013045; rev:3; metadata:created_at 2011_06_16, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_04_20;)

Jun 16, 2011, 12:00 PM

Apr 20, 2020, 12:00 PM

Jun 16, 2011, 12:00 PM

Dec 19, 2025, 10:34 PM

rules/emerging-malware.rules