ET ADWARE_PUP Spyhealer Fake Anti-Spyware Install User-Agent (SpyHealer)

SID: 2003399Rev: 110 views
History
Sourceet/open
CreatedJuly 30, 2010
UpdatedMarch 2, 2024
Classificationpup-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET ADWARE_PUP Spyhealer Fake Anti-Spyware Install User-Agent (SpyHealer)"; flow:established,to_server; http.user_agent; content:"SpyHeal"; startswith; nocase; classtype:pup-activity; sid:2003399; rev:11; metadata:attack_target Client_Endpoint, created_at 2010_07_30, deployment Perimeter, confidence High, signature_severity Minor, updated_at 2024_03_02, mitre_tactic_id TA0009, mitre_tactic_name Collection, mitre_technique_id T1005, mitre_technique_name Data_from_local_system;)

Metadata

attack targetClient_Endpoint
created at2010_07_30
deploymentPerimeter
confidenceHigh
signature severityMinor
updated at2024_03_02
mitre tactic idTA0009
mitre tactic nameCollection
mitre technique idT1005
mitre technique nameData_from_local_system

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!