James_inthe_box

Hvnc snort/suricata sig

Jun 28th, 2019
1,067
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.23 KB | None | 0 0
  1. alert tcp any any -> any 443 (msg:"HVNC Variant 3 Checkin"; flow:established,to_server; dsize:<200; content:"|2d 55 53 52 2d|"; offset:4 ; depth:20; rawbytes; classtype:trojan-activity; sid:20166296; rev:1; metadata:created_at 2019_06_28;)
Add Comment
Please, Sign In to add comment