ET POLICY Possible Ecard Trojan download
Sourceet/open
CreatedJuly 30, 2010
UpdatedMay 4, 2023
Classificationsuspicious-filename-detect
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Possible Ecard Trojan download"; flow:established,to_server; content:".exe"; nocase; http_uri; pcre:"/(gif|car(d|tao)|jpe?g)\.exe$/Ui"; classtype:suspicious-filename-detect; sid:2006434; rev:9; metadata:created_at 2010_07_30, deployment Perimeter, deprecation_reason Age, confidence Low, signature_severity Informational, updated_at 2023_05_04;)
Metadata
created at2010_07_30
deploymentPerimeter
deprecation reasonAge
confidenceLow
signature severityInformational
updated at2023_05_04
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!