Advertisement
James_inthe_box

AvaMaria snort suricata

Dec 14th, 2018
540
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.32 KB | None | 0 0
  1. alert tcp $EXTERNAL_NET !$HTTP_PORTS -> $HOME_NET any (msg:"TROJAN AveMaria Initial Checkin"; flow:established,from_server; dsize:<15; content:"|29 bb 66 e4 00 00 00 00|"; depth:15; reference:url,app.any.run/tasks/67362469-76df-4b19-bfda-5d95a2b4d179; classtype:trojan-activity; sid:20166275; rev:1; metadata:created_at 2018_12_18;)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement