Versions (3)
Version DetailsCurrent
Rev: 7 • May 9, 2014, 12:00 PMET MALWARE W32/Fsysna.Downloader CnC Beacon
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Fsysna.Downloader CnC Beacon"; flow:established,to_server; http.method; content:"GET"; http.uri; content:".php"; http.header; content:"Content-Type|3a 20|*/*|0d 0a|"; depth:19; http.user_agent; content:"Mozilla/4.0 (compatible|3B 20|MSIE "; content:".0|3B 20|Win32|29 3B 20|"; distance:1; within:15; fast_pattern; pcre:"/^\d+$/R"; reference:url,blogs.mcafee.com/mcafee-labs/targeted-attacks-japanese-firm-use-old-activex-vulnerability; reference:md5,2b91011e122364148698a249c2f4b7fe; reference:md5,6c040be9d91083ffba59405f9b2c89bf; classtype:command-and-control; sid:2018462; rev:7; metadata:attack_target Client_Endpoint, created_at 2014_05_09, deployment Perimeter, deprecation_reason Relevance, signature_severity Major, tag c2, updated_at 2024_03_06, reviewed_at 2024_03_06, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel;)
May 9, 2014, 12:00 PM
Mar 6, 2024, 12:00 PM
Sep 21, 2024, 3:00 AM
May 30, 2025, 12:04 AM
rules/emerging-malware.rules