ESET Online Help

Search English
Select the topic

Working with URLs

Common behavior among malware is downloading additional parts of malware or malware configuration data from publicly available data sharing services such as pastebin.com. We want to monitor each access to pastebin.com. We need to filter out valid cases, such as a user browsing the internet on purpose, and we can choose to use the popularity property.

Rule

Things to notice in the rule example above:

1.As pastebin.com may have different IPs associated, we are matching URL pastebin.com directly.