ET MALWARE Possible Locky AlphaNum Downloader Oct 3 2016
Sourceet/open
CreatedOctober 3, 2016
UpdatedMarch 2, 2024
Classificationtrojan-activity
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET MALWARE Possible Locky AlphaNum Downloader Oct 3 2016"; flow:established,to_client; flowbits:isnotset,ET.http.binary; flowbits:isset,ET.LockyDL; http.header_names; content:!"|0d 0a|Cookie|0d 0a|"; content:!"|0d 0a|Content-Disposition|0d 0a|"; content:"|0d 0a|ETag|0d 0a|"; http.content_len; bsize:6; content:"1"; fast_pattern; startswith; pcre:"/^1[6-8]\d{4}$/m"; file.data; content:!"MZ"; within:2; content:!"PK"; within:2; content:!"GIF"; within:3; content:!"|FF D8 FF|"; within:3; content:!"CWS"; within:3; content:!"ZWS"; within:3; pcre:"/^.{4}[\x0a-\x7f]{0,100}[\x00-x09\x80-\xff]/s"; classtype:trojan-activity; sid:2023316; rev:4; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_10_03, deployment Perimeter, malware_family Locky, confidence Medium, signature_severity Major, updated_at 2024_03_02;)
Metadata
affected productWindows_XP_Vista_7_8_10_Server_32_64_Bit
attack targetClient_Endpoint
created at2016_10_03
deploymentPerimeter
malware familyLocky
confidenceMedium
signature severityMajor
updated at2024_03_02
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!