Back to Rule

Rule History

SID: 2021094 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 5May 14, 2015, 12:00 PM

ET ADWARE_PUP Win32/Toolbar.Conduit.AG Checkin

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP Win32/Toolbar.Conduit.AG Checkin"; flow:to_server,established; urilen:1; http.method; content:"POST"; http.user_agent; content:"NSIS_Inetc (Mozilla)"; bsize:20; http.request_body; content:"postInstallReport"; fast_pattern; content:"machineId|22 3a 22|"; reference:md5,8fc00c6696268ae42411a5ebf9d2576f; classtype:pup-activity; sid:2021094; rev:5; metadata:created_at 2015_05_14, signature_severity Minor, updated_at 2020_08_31;)

May 14, 2015, 12:00 PM

Aug 31, 2020, 12:00 PM

May 14, 2015, 12:00 PM

Sep 10, 2024, 1:01 PM

rules/emerging-adware_pup.rules