ET WEB_CLIENT Fake MS Security Update (Jar)

SID: 2017549Rev: 313 views
History
Sourceet/open
CreatedOctober 2, 2013
UpdatedOctober 8, 2019
Classificationexploit-kit
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Fake MS Security Update (Jar)"; flow:established,from_server; file_data; content:"Microsoft Security Update"; content:"applet_ssv_validated"; fast_pattern; flowbits:set,et.exploitkitlanding; classtype:exploit-kit; sid:2017549; rev:3; metadata:created_at 2013_10_02, signature_severity Major, updated_at 2019_10_08;)

Metadata

created at2013_10_02
signature severityMajor
updated at2019_10_08

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!