ET INFO WinHttpRequest Downloading EXE

SID: 2019822Rev: 81 views
History
Sourceet/open
CreatedDecember 1, 2014
UpdatedApril 20, 2023
Classificationmisc-activity
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET INFO WinHttpRequest Downloading EXE"; flow:established,from_server; flowbits:isset,et.WinHttpRequest; file_data; content:"MZ"; within:2; byte_jump:4,58,relative,little; content:"PE|00 00|"; distance:-64; within:4; classtype:misc-activity; sid:2019822; rev:8; metadata:attack_target Client_and_Server, created_at 2014_12_01, deployment Perimeter, confidence High, signature_severity Informational, updated_at 2023_04_20;)

Metadata

attack targetClient_and_Server
created at2014_12_01
deploymentPerimeter
confidenceHigh
signature severityInformational
updated at2023_04_20

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!