alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M2"; flow:established,to_server; content:"/counter/?"; http_uri; fast_pattern:only; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:!"User-Agent|3a|"; http_header; pcre:"/\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; classtype:trojan-activity; sid:2024036; rev:3;)

Added 2017-03-20 19:16:55 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M2"; flow:established,to_server; content:"/counter/?"; http_uri; fast_pattern:only; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:!"User-Agent|3a|"; http_header; pcre:"/\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; classtype:trojan-activity; sid:2024036; rev:3;)

Added 2017-03-17 17:48:44 UTC


alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN WS/JS Downloader Mar 07 2017 M2"; flow:established,to_server; content:"/counter/?"; depth:10; http_uri; fast_pattern; pcre:"/^\/counter\/(?:\?[a-z]?\d{1,2}$|[^\x2f]*\d\.exe$|.*?[?=](?=[A-Za-z_-]{0,200}[0-9][A-Za-z_-]{0,200}[0-9])(?=[A-Z0-9_-]{0,200}[a-z][A-Z0-9_-]{0,200}[a-z])(?=[a-z0-9_-]{0,200}[A-Z][a-z0-9_-]{0,200}[A-Z])[A-Za-z0-9_-]{50,}(?:&|$))/U"; content:!"Referer|3a|"; http_header; content:!"Cookie|3a|"; content:!"User-Agent|3a|"; http_header; classtype:trojan-activity; sid:2024036; rev:2;)

Added 2017-03-08 18:54:41 UTC


Topic revision: r1 - 2017-03-20 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats