Back to Rule

Rule History

SID: 2016391 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 3Feb 8, 2013, 12:00 PM

ET DELETED Adobe Flash Zero Day LadyBoyle Infection Campaign

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET DELETED Adobe Flash Zero Day LadyBoyle Infection Campaign"; flow:established,to_client; file_data; content:"FWS"; distance:0; content:"LadyBoyle"; distance:0; reference:md5,3de314089db35af9baaeefc598f09b23; reference:md5,2568615875525003688839cb8950aeae; reference:url,blog.fireeye.com/research/2013/02/lady-boyle-comes-to-town-with-a-new-exploit.html; reference:url,www.adobe.com/go/apsb13-04; reference:cve,2013-0633; reference:cve,2013-0633; classtype:trojan-activity; sid:2016391; rev:3; metadata:created_at 2013_02_08, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_09_09;)

Feb 8, 2013, 12:00 PM

Sep 9, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 13, 2025, 9:34 PM

rules/emerging-deleted.rules