Back to Rule

Rule History

SID: 5000003 • Source: malsilo/win-malware

Versions (2)

Version DetailsCurrent

Rev: 1Dec 1, 2022, 12:00 PM

MalSilo MALWARE (tasker) DNS Lookup

alert dns $HOME_NET any -> any any (msg:"MalSilo MALWARE (tasker) DNS Lookup"; dns_query; content:"clipper.guru"; nocase; depth:12; isdataat:!1,relative; fast_pattern; reference:url,malsilo.gitlab.io/feeds/dumps/master-feed.json; classtype:trojan-activity; sid:5000003; rev:1; metadata:tag peexe32, tag pegui, tag assembly, created_at 2022_12_01, malware_family tasker, updated_at 2022_12_01;)

Dec 1, 2022, 12:00 PM

Dec 1, 2022, 12:00 PM

Jun 12, 2025, 7:35 PM

Jun 12, 2025, 7:35 PM

malsilo-dns.rules