title: Chafer Malware URL Pattern id: fb502828-2db0-438e-93e6-801c7548686d status: test description: Detects HTTP requests used by Chafer malware references: - https://securelist.com/chafer-used-remexi-malware/89538/ author: Florian Roth date: 2019/01/31 modified: 2022/08/15 tags: - attack.command_and_control - attack.t1071.001 logsource: category: proxy detection: selection: c-uri|contains: '/asp.asp\?ui=' condition: selection fields: - ClientIP - c-uri - c-useragent falsepositives: - Unknown level: critical