""ET WEB_CLIENT Tech Support Scam Landing M2 2019-04-15""
SID: 2027198
Revision: 3
Class Type: trojan-activity
Metadata: created_at 2019_04_15, tag Tech_Support_Scam, tag Malvertising, updated_at 2019_08_16
Reference:
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: $HTTP_PORTS
Destination Network: $HOME_NET
Destination Port: any
Flow: established,from_server
Contents:
-
Value: "200"
-
Value: "createOscillator|28 29|"
-
Value: "createGain|28 29|"
-
Value: "|3e|System|20|Warning!|3c 2f|span|3e|"
-
Value: "|3c|b|3e|Windows|20|Version"
Within:
PCRE:
Special Options:
-
http_stat_code
-
file_data
-
fast_pattern