Advertisement
James_inthe_box

Puntoloader snort/suricata rule

Feb 19th, 2019
591
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.31 KB | None | 0 0
  1. alert tcp any any -> any !$HTTP_PORTS (msg:"Punto Loader Checkin"; flow:established,to_server; content:"POST"; http_method; content:"klog.php"; http_uri; content:"Accept|3a| text|2f|html|3b|q=0|2e|7|2c 20 2a 2f 2a 3b|q=1"; http_header; classtype:trojan-activity; sid:20166287; rev:1; metadata:created_at 2019_02_19;)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement