Back to Rule

Rule History

SID: 2016432 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 6Feb 20, 2013, 12:00 PM

ET MALWARE Likseput.B Checkin

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Likseput.B Checkin"; flow:established,to_server; http.user_agent; content:"|3b|Trident/4.0"; fast_pattern; pcre:"/^[^\r\n]+[^\x20]\x3bTrident\/4\.0\x29\s\d{2}\x3a\d{2}\s$/i"; reference:md5,95d85aa629a786bb67439a064c4349ec; classtype:command-and-control; sid:2016432; rev:6; metadata:created_at 2013_02_20, signature_severity Major, updated_at 2024_03_10;)

Feb 20, 2013, 12:00 PM

Mar 10, 2024, 12:00 PM

Feb 20, 2013, 12:00 PM

Sep 10, 2024, 1:01 PM

rules/emerging-malware.rules