ET MALWARE Koobface Checkin via POST

SID: 2009156Rev: 120 views
History
Sourceet/open
CreatedSeptember 28, 2010
UpdatedNovember 19, 2020
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Koobface Checkin via POST"; flow:to_server,established; http.method; content:"POST"; http.uri; content:".php"; nocase; http.request_body; content:"f="; content:"&a="; content:"&v="; content:"&c="; content:"&s="; content:"&l="; content:"&ck="; content:"&c_fb="; content:"&c_ms="; content:"&c_hi="; content:"&c_be="; content:"&c_fr="; content:"&c_yb="; reference:url,www.virustotal.com/analisis/a4a854e56ecc0a54204fc3b043c63094; classtype:command-and-control; sid:2009156; rev:12; metadata:created_at 2010_09_28, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_11_19;)

Metadata

created at2010_09_28
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2020_11_19

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!