title: Flash Player Update from Suspicious Location id: 4922a5dd-6743-4fc2-8e81-144374280997 status: test description: Detects a flashplayer update from an unofficial location author: Florian Roth references: - https://gist.github.com/roycewilliams/a723aaf8a6ac3ba4f817847610935cfb date: 2017/10/25 modified: 2022/01/07 logsource: category: proxy detection: selection: - c-uri-query|contains: '/flash_install.php' - c-uri-query|endswith: '/install_flash_player.exe' filter: c-uri-stem|contains: '.adobe.com/' condition: selection and not filter falsepositives: - Unknown flash download locations level: high tags: - attack.initial_access - attack.t1189 - attack.execution - attack.t1204.002 - attack.defense_evasion - attack.t1036.005