Back to Rule

Rule History

SID: 2021984 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 4Oct 21, 2015, 12:00 PM

ET ADWARE_PUP OSX/Fake Flash Player Download Oct 20

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP OSX/Fake Flash Player Download Oct 20"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/download/"; content:"/FMP.dmg?download_browser="; distance:0; fast_pattern; content:"&app_id="; distance:0; content:"&campaign="; distance:0; content:"&cargoType="; distance:0; content:"&oname=FMP.dmg"; distance:0; classtype:pup-activity; sid:2021984; rev:4; metadata:created_at 2015_10_21, signature_severity Minor, updated_at 2020_08_31;)

Oct 21, 2015, 12:00 PM

Aug 31, 2020, 12:00 PM

Oct 21, 2015, 12:00 PM

Sep 10, 2024, 1:01 PM

rules/emerging-adware_pup.rules