MALWARE-OTHER --
MALWARE-OTHER Win.Trojan.WinOS4 download attempt
This rule alerts on file downloads of Win.Trojan.WinOS4. WinOS 4.0 is an post-exploitation framework derived from ghostRat that is used to establish persistent access to an infected machine.
This rule alerts on file downloads of Win.Trojan.WinOS4.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None