alert http $HOME_NET any -> $EXTERNAL_NET any (
msg:"ET MALWARE Win32/LeftHook Stealer CnC Activity (GET) M1";
flow:established,to_server;
urilen:46;
http.method;
content:"GET";
http.uri;
content:"/getid.php?id="; startswith; fast_pattern;
pcre:"/^[a-z]{32}$/R";
http.host;
pcre:"/^(?:[0-9]{1,3}\.){3}[0-9]{1,3}$/";
http.connection;
content:"close"; bsize:5;
http.header_names;
content:"|0d 0a|Host|0d 0a|Connection|0d 0a 0d 0a|"; bsize:22;
reference:md5,43967615d9e0e19bc59d32fdb5afd7e4;
reference:url,twitter.com/Jane_0sint/status/1648075834702413830;
classtype:trojan-activity;
sid:2044999; rev:1;
metadata:attack_target Client_Endpoint, created_at 2023_04_17, deployment Perimeter, malware_family Win32_LeftHook, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_04_18;
)