ET ADWARE_PUP W32/Linkular.Adware Successful Install Beacon (2)


Query · suricata

flow:established,to_server;
http.uri;
content:"/api/software/?s="; fast_pattern;
content:"&os=";
content:"&output=";
content:"&v=";
content:"&l=";
content:"&np=";
content:"&osv=";
content:"&b=";
content:"&bv=";
content:"&c=";
content:"&cv=";
Raw source ET ADWARE_PUP W32/Linkular.Adware Successful Install Beacon (2) · Suricata
Esc
Published by Emerging Threats Open ↗, licensed under BSD 3-Clause ↗. Line breaks added for readability; the rule is otherwise unchanged.
alert http $HOME_NET any -> $EXTERNAL_NET any (
    msg:"ET ADWARE_PUP W32/Linkular.Adware Successful Install Beacon (2)";
    flow:established,to_server;
    http.uri;
    content:"/api/software/?s="; fast_pattern;
    content:"&os=";
    content:"&output=";
    content:"&v=";
    content:"&l=";
    content:"&np=";
    content:"&osv=";
    content:"&b=";
    content:"&bv=";
    content:"&c=";
    content:"&cv=";
    reference:url,webroot.com/blog/2014/03/25/deceptive-ads-expose-users-adware-linkularwin32-speedupmypc-puas-potentially-unwanted-applications/;
    classtype:pup-activity;
    sid:2018323; rev:6;
    metadata:attack_target Client_Endpoint, created_at 2014_03_26, deployment Perimeter, signature_severity Minor, tag c2, updated_at 2020_10_12, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1041, mitre_technique_name Exfiltration_Over_C2_Channel;
)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.