Back to Rule

Rule History

SID: 2034697 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 2Dec 13, 2021, 12:00 PM

ET MALWARE Possible Kimsuky Related Malicious VBScript

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Possible Kimsuky Related Malicious VBScript"; flow:established,to_client; http.stat_code; content:"200"; http.header; content:"Content-Encoding|3a 20|gzip"; http.response_body; content:"language|3d|javascript|3e|document|2e|write|28|unescape|28 27|"; content:"%47%65%74%4F%62%6A%65%63%74%28%22%22%6E%65%77%3A"; content:"%2E%76%62%73%20%26%40%65%63%68%6F%20%55%52%4C%20%3D%20%22%22"; distance:0; within:285; fast_pattern; content:"%73%65%6C%66%2E%63%6C%6F%73%65"; reference:md5,d74f268b986fecfa03b81029dd134811; classtype:trojan-activity; sid:2034697; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2021_12_13, deployment Perimeter, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_04_18;)

Dec 13, 2021, 12:00 PM

Apr 18, 2022, 12:00 PM

Sep 21, 2024, 3:00 AM

Sep 8, 2025, 9:34 PM

rules/emerging-malware.rules