ET HUNTING VibeCoded MSI Installer VBS Script Inbound
Sourceet/open
CreatedMarch 24, 2026
UpdatedMarch 24, 2026
Classificationmisc-activity
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET HUNTING VibeCoded MSI Installer VBS Script Inbound"; flow:established,to_client; http.response_body; content:"|27 20|MSI|20|Installer|20|Script"; startswith; fast_pattern; content:"Const|20|MSI|5f|URL"; distance:0; content:"Const|20|MSI|5f|NAME|20 3d|"; distance:0; content:"Const|20|LOG|5f|FILE|20 3d|"; distance:0; classtype:misc-activity; sid:2068411; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2026_03_24, deployment Perimeter, deployment SSLDecrypt, confidence High, signature_severity Informational, updated_at 2026_03_24, mitre_tactic_id TA0002, mitre_tactic_name Execution, mitre_technique_id T1072, mitre_technique_name Software_Deployment_Tools; target:dest_ip;)
Metadata
affected productWindows_XP_Vista_7_8_10_Server_32_64_Bit
attack targetClient_Endpoint
tls stateTLSDecrypt
created at2026_03_24
deploymentSSLDecrypt
confidenceHigh
signature severityInformational
updated at2026_03_24
mitre tactic idTA0002
mitre tactic nameExecution
mitre technique idT1072
mitre technique nameSoftware_Deployment_Tools
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!