ET MALWARE Possible Stitur Secondary Download

SID: 2017700Rev: 50 views
History
Sourceet/open
CreatedNovember 9, 2013
UpdatedSeptember 22, 2020
Classificationtrojan-activity
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Possible Stitur Secondary Download"; flow:established,from_server; http.header; content:".file|0d 0a|"; fast_pattern; content:"Content-Description|3a 20|File Transfer|0d 0a|"; content:"Content-Transfer-Encoding|3a 20|binary|0d 0a|"; pcre:"/filename=[a-f0-9]{13}\.file\r\n/"; classtype:trojan-activity; sid:2017700; rev:5; metadata:created_at 2013_11_09, confidence Medium, signature_severity Major, updated_at 2020_09_22;)

Metadata

created at2013_11_09
confidenceMedium
signature severityMajor
updated at2020_09_22

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!