Back to Rule

Rule History

SID: 2020171 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 5Jan 13, 2015, 12:00 PM

ET MALWARE Hong Kong SWC Attack DNS Lookup (aoemvp.com)

alert dns $HOME_NET any -> any any (msg:"ET MALWARE Hong Kong SWC Attack DNS Lookup (aoemvp.com)"; dns.query; content:"aoemvp.com"; depth:10; nocase; endswith; fast_pattern; reference:url,blog.dragonthreatlabs.com/2015/01/dtl-12012015-01-hong-kong-swc-attack.html; classtype:trojan-activity; sid:2020171; rev:5; metadata:created_at 2015_01_13, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_17;)

Jan 13, 2015, 12:00 PM

Sep 17, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 8, 2025, 9:38 PM

rules/emerging-malware.rules