Back to Rule

Rule History

SID: 2024779 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 7Sep 27, 2017, 12:00 PM

ET DELETED DNS Query For Browser Cryptocurrency Mining Domain

alert dns $HOME_NET any -> any any (msg:"ET DELETED DNS Query For Browser Cryptocurrency Mining Domain"; content:"|06|static|0a|reasedoper|02|pw|00|"; fast_pattern; nocase; reference:url,www.welivesecurity.com/2017/09/14/cryptocurrency-web-mining-union-profit/; classtype:coin-mining; sid:2024779; rev:7; metadata:affected_product Web_Browsers, created_at 2017_09_27, malware_family CoinMiner, signature_severity Minor, updated_at 2023_05_09;)

Sep 27, 2017, 12:00 PM

May 9, 2023, 12:00 PM

Sep 27, 2017, 12:00 PM

May 31, 2024, 9:00 PM

rules/emerging-deleted.rules