AvaMaria snort suricata
James_inthe_box Dec 14th, 2018 302 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
- alert tcp $EXTERNAL_NET !$HTTP_PORTS -> $HOME_NET any (msg:"TROJAN AveMaria Initial Checkin"; flow:established,from_server; dsize:<15; content:"|29 bb 66 e4 00 00 00 00|"; depth:15; reference:url,app.any.run/tasks/67362469-76df-4b19-bfda-5d95a2b4d179; classtype:trojan-activity; sid:20166275; rev:1; metadata:created_at 2018_12_18;)
RAW Paste Data