title: Chafer Malware URL Pattern id: fb502828-2db0-438e-93e6-801c7548686d status: test description: Detects HTTP requests used by Chafer malware author: Florian Roth references: - https://securelist.com/chafer-used-remexi-malware/89538/ date: 2019/01/31 modified: 2021/11/27 logsource: category: proxy detection: selection: c-uri|contains: '/asp.asp?ui=' condition: selection fields: - ClientIP - c-uri - c-useragent falsepositives: - Unknown level: critical tags: - attack.command_and_control - attack.t1071.001