Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"401TRG MALWARE VBA.StealthLoader Checkin"; flow:to_server,established; content:"&D="; http_client_body; depth:3; content:"&U="; http_client_body; distance:0; content:"&OS="; http_client_body; distance:0; content:"&OSA="; http_client_body; distance:0; content:"&PR="; http_client_body; distance:0; content:"%7C"; http_client_body; distance:0; reference:md5,74487b631e5688ad6affdd23340563bd; reference:url,twitter.com/James_inthe_box/status/1204819761642688512; classtype:trojan-activity; sid:7703947; rev:1;)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement