Flash Player Update from Suspicious Location

 Original Source: [Sigma source]
Title: Flash Player Update from Suspicious Location
Status: test
Description:Detects a flashplayer update from an unofficial location
References:
  -https://gist.github.com/roycewilliams/a723aaf8a6ac3ba4f817847610935cfb
Author: Florian Roth (Nextron Systems)
Date: 2017-10-25
modified:2022-08-08
Tags:
  • -'attack.initial-access'
  • -'attack.stealth'
  • -'attack.t1189'
  • -'attack.execution'
  • -'attack.t1204.002'
  • -'attack.t1036.005'
Logsource:
  • category: proxy
Detection:
  selection:
c-uri|contains:'/flash_install.php' c-uri|endswith:'/install_flash_player.exe'   filter:
    cs-host|endswith: '.adobe.com'
  condition:selection and not filter
Falsepositives:
  -Unknown flash download locations
Level: high