Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- rule shade_02_2019 {
- strings:
- $s1="\\torrc-defaults"
- $s2="@mail.ru"
- $s3=",\"data\":\""
- $s4="\"index\":"
- $s5="\"block\":"
- $s6="\"base\":"
- $s7=",\"found\":["
- $s8="{\"type\":1,\"report\":{\"id\":"
- $s9="s.com/ip/"
- $s10="mail,smtp,mailgate,relay"
- $s11="http://www.anti-abuse.org/multi-rbl-check-results/?host="
- $s12="http://whatismyipaddress.com/"
- $s13="//whatismyipaddress.com/ip/"
- $s14="http://whatsmyip.net/"
- $s15="WindowsSessionManager.lnk"
- $s16="/reg.php?"
- $s17="hW[] = "
- $s18="upd.php?"
- $s19="/task.php?"
- $s20="/rep.php"
- $s21="/ip.php"
- $s22="nocache="
- $s23="!update"
- $s24="!sleep"
- $s25="!reg"
- $s26="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\"
- $s27="--ignore-missing-torrc"
- $s28=".onion"
- $s29="csrss.exe"
- $s30="services"
- condition:
- (17 of them)
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement