ET HUNTING Suspicious Zipped Filename in Outbound POST Request (Mozilla_Firefox_Cookies) M1
Sourceet/open
CreatedApril 24, 2019
UpdatedAugust 28, 2020
Classificationtrojan-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING Suspicious Zipped Filename in Outbound POST Request (Mozilla_Firefox_Cookies) M1"; flow:established,to_server; http.method; content:"POST"; http.request_body; content:"PK"; depth:2; content:"Mozilla_Firefox_Cookies"; distance:26; within:100; nocase; fast_pattern; classtype:trojan-activity; sid:2027278; rev:2; metadata:attack_target Client_and_Server, created_at 2019_04_24, deployment Perimeter, performance_impact Low, confidence Medium, signature_severity Major, tag T1002, tag data_compressed, updated_at 2020_08_28;)
Metadata
attack targetClient_and_Server
created at2019_04_24
deploymentPerimeter
performance impactLow
confidenceMedium
signature severityMajor
tagdata_compressed
updated at2020_08_28
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!