ET MALWARE W32/Nymaim Checkin M2

SID: 2016757Rev: 110 views
History
Sourceet/open
CreatedApril 16, 2013
UpdatedOctober 20, 2022
Classificationcommand-and-control
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE W32/Nymaim Checkin M2"; flow:to_server,established; http.method; content:"POST"; http.content_type; content:"application/x-www-form-urlencoded"; nocase; bsize:33; http.user_agent; content:"|20|MSIE|20|"; http.request_body; content:"filename="; depth:9; fast_pattern; content:"&data="; distance:0; pcre:"/^filename=[a-z]+?\.[a-z]+?&data=/"; http.header_names; content:!"Referer"; classtype:command-and-control; sid:2016757; rev:11; metadata:created_at 2013_04_16, signature_severity Major, updated_at 2022_10_20;)

Metadata

created at2013_04_16
signature severityMajor
updated at2022_10_20

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!