Versions (2)
Version DetailsCurrent
Rev: 7 • May 29, 2013, 12:00 PMET MALWARE Spy/Infostealer.Win32.Embed.A Client Traffic
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Spy/Infostealer.Win32.Embed.A Client Traffic"; flow:established,to_server; http.uri; content:"/search?hl="; content:"q="; content:"meta="; fast_pattern; pcre:"/meta=(?:(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4}))?(?:&?id=[a-z]+)?$/"; http.host; content:!"sogou.com"; http.user_agent; content:"Windows NT 5."; http.header_names; content:!"Referer|0d 0a|"; content:!"Accept"; reference:url,contagiodump.blogspot.no/2011/01/jan-6-cve-2010-3333-with-info-theft.html; classtype:trojan-activity; sid:2016932; rev:7; metadata:attack_target Client_Endpoint, created_at 2013_05_29, deployment Perimeter, malware_family HIMAN, performance_impact Moderate, signature_severity Major, updated_at 2020_10_08;)May 29, 2013, 12:00 PM
Oct 8, 2020, 12:00 PM
May 29, 2013, 12:00 PM
May 31, 2024, 9:00 PM
rules/emerging-malware.rules