ET MALWARE AutoIt3 Script Downloaded via Powershell Shortly After AutoIt3.exe Download
Query · suricata
flow:established,to_server; flowbits:isset,ET.AutoItDownload; http.method; content:"GET"; http.uri; content:".au3"; endswith; http.user_agent; content:"WindowsPowerShell/"; fast_pattern; http.header_names; content:!"|0d 0a|Referer|0d 0a|"; nocase; threshold:type limit, count 1, seconds 300, track by_src;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.AutoItDownload