""ET MALWARE W32/DownloadAdmin.Adware User-Agent""

SID: 2021564

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2015_07_31, updated_at 2019_08_14

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "User-Agent|3a 20|Installer|28|ref=|5b|"

  • Value: "|3b|windows="

  • Value: "|3b|uac="

  • Value: "|3b|elevated="

  • Value: "|3b|dotnet="

  • Value: "|3b|startTime="

  • Value: "|3b|pid="

Within:

PCRE:

Special Options:

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

source