""ET WEB_CLIENT Tech Support Scam Landing M1 2019-04-15""
SID: 2027197
Revision: 3
Class Type: trojan-activity
Metadata: created_at 2019_04_15, tag Tech_Support_Scam, tag Malvertising, updated_at 2019_08_16
Reference:
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: $HTTP_PORTS
Destination Network: $HOME_NET
Destination Port: any
Flow: established,from_server
Contents:
-
Value: "200"
-
Value: "alert|28 22|Windows|20|Firewall|20|has|20|detected|20|that|20|your|20|Windows"
-
Value: "system|20|files|20|are|20|automatically|20|deleted"
-
Value: "Please|20|follow|20|the|20|instructions"
Within: 200
PCRE:
Special Options:
-
http_stat_code
-
file_data
-
fast_pattern