Versions (3)
Version DetailsCurrent
Rev: 8 • Jun 2, 2014, 12:00 PMET ADWARE_PUP Adware.MultiInstaller
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP Adware.MultiInstaller"; flow:established, to_server; http.method; content:"GET"; http.uri; content:"?s1="; fast_pattern; pcre:"/^\/(?:info|entrance|start|debug)\?s1=[a-f0-9]{100,}$/"; http.header_names; content:!"Referer"; reference:md5,26973eeddb4781225b7c23d2d9cce996; reference:md5,a74b1602a50b9c7d3262e3f80a6a2e68; classtype:pup-activity; sid:2018512; rev:8; metadata:created_at 2014_06_02, signature_severity Minor, updated_at 2020_08_31;)Jun 2, 2014, 12:00 PM
Aug 31, 2020, 12:00 PM
Jun 2, 2014, 12:00 PM
Sep 10, 2024, 1:01 PM
rules/emerging-adware_pup.rules