Back to Rule

Rule History

SID: 2018033 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 5Jan 29, 2014, 12:00 PM

ET MALWARE Win32.Genome.boescz Checkin

alert tcp $HOME_NET any -> $EXTERNAL_NET [25,587] (msg:"ET MALWARE Win32.Genome.boescz Checkin"; flow:to_server,established; content:"|0d 0a|Subject|3a 20|TenInfect"; fast_pattern; content:"|0d 0a 0d 0a|TenInfect"; distance:0; reference:md5,313535d09865f3629423cd0e9b2903b2; reference:url,www.virustotal.com/en/file/75c454bbcfc06375ad1e8b45d4167d7830083202f06c6309146e9a4870cddfba/analysis/; classtype:command-and-control; sid:2018033; rev:5; metadata:created_at 2014_01_29, deprecation_reason Age, signature_severity Major, updated_at 2024_02_14, reviewed_at 2024_02_14;)

Jan 29, 2014, 12:00 PM

Feb 14, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-malware.rules