Back to Rule

Rule History

SID: 5000012 • Source: malsilo/win-malware

Versions (2)

Version DetailsCurrent

Rev: 1Dec 1, 2022, 12:00 PM

MalSilo MALWARE (tasker) Detected

alert http any any -> $EXTERNAL_NET any (msg:"MalSilo MALWARE (tasker) Detected"; flow:established,to_server; content:"clipper.guru"; http_host; depth:12; fast_pattern; content:"/bot/online"; nocase; depth:11; http_uri; reference:url,malsilo.gitlab.io/feeds/dumps/master-feed.json; classtype:trojan-activity; sid:5000012; rev:1; metadata:tag peexe32, tag pegui, tag assembly, created_at 2022_12_01, malware_family tasker, updated_at 2022_12_01;)

Dec 1, 2022, 12:00 PM

Dec 1, 2022, 12:00 PM

Jun 12, 2025, 7:35 PM

Jun 12, 2025, 7:35 PM

malsilo-url.rules