ET MALWARE WebDAV Retrieving .vbs from .url M1 (CVE-2023-36025)
Query · suricata
flow:established,to_client; xbits:isset,ET.PROPFIND,track ip_dst; http.stat_code; content:"200"; http.content_type; content:"application/x-mswinurl"; bsize:22; file.data; content:"[InternetShortcut]"; content:"URL=file://"; distance:0; fast_pattern; content:".vbs"; distance:0;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.PROPFIND