Back to Rule

Rule History

SID: 2039031 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 2Sep 27, 2022, 12:00 PM

ET MALWARE TA569 Fake Browser Update

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE TA569 Fake Browser Update"; flow:established,to_client; http.response_body; content:"|3c|a|20|href|3d 22 2f|download|2e|php|3f|filename|3d|file|2f|2|2e|png|22 20|download"; content:"onclick|3d 22|event|2e|preventDefault|28 29 3b 20|document|2e|getElementById|28 27|logout|2d|form|27 29 2e|submit|28 29 3b 22|"; distance:0; content:"|d0 a1 d0 ba d0 b0 d1 87 d0 b0 d1 82 d1 8c 20 d1 84 d0 b0 d0 b9 d0 bb|"; distance:0; fast_pattern; content:"|3c|form|20|id|3d 22|logout|2d|form|22 20|action|3d 22 2f|download|2e|php|3f|filename|3d|file|2f|2|2e|png|22 20|method|3d 22|POST|22 20|style|3d 22|display|3a 20|none|3b 22 3e|"; distance:0; reference:md5,608b6e77c490d25520df2795881ff959; classtype:trojan-activity; sid:2039031; rev:2; metadata:attack_target Client_Endpoint, created_at 2022_09_27, deployment Perimeter, deployment SSLDecrypt, deprecation_reason Age, malware_family TA569, performance_impact Low, confidence High, signature_severity Major, tag compromised_website, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_03_02;)

Sep 27, 2022, 12:00 PM

Mar 2, 2023, 12:00 PM

Sep 21, 2024, 3:00 AM

Aug 29, 2025, 8:34 PM

rules/emerging-malware.rules