ET MALWARE Win32.Chroject.B Receiving ClickFraud Commands from CnC 1
Sourceet/open
CreatedMarch 25, 2015
UpdatedMarch 17, 2022
Classificationcommand-and-control
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Win32.Chroject.B Receiving ClickFraud Commands from CnC 1"; flow:from_server,established; file_data; content:"/title><script>window.setTimeout(function () { window.location="; fast_pattern; content:"<title>"; pcre:"/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})<\/title/R"; reference:md5,586ad13656f4595723b481d77b6bfb09; classtype:command-and-control; sid:2020748; rev:8; metadata:created_at 2015_03_25, signature_severity Major, updated_at 2022_03_17;)
References
| md5 | 586ad13656f4595723b481d77b6bfb09 |
Metadata
created at2015_03_25
signature severityMajor
updated at2022_03_17
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!