ET MALWARE W32/Yaq Checkin
Sourceet/open
CreatedNovember 11, 2011
UpdatedFebruary 8, 2024
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Yaq Checkin"; flow:established,to_server; http.uri; content:"/Submit.php?id="; content:"&action="; within:10; content:"&mac="; within:10; content:"&lockcode="; within:30; content:"&homepc="; within:15; http.user_agent; bsize:7; content:"getinfo"; classtype:command-and-control; sid:2013900; rev:3; metadata:created_at 2011_11_11, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_02_08;)
Metadata
created at2011_11_11
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2024_02_08
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!