Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- alert tcp any any -> any $HTTP_PORTS (msg:"RocketX Infostealer"; flow:to_server,established; content:"POST"; http_method; content:"hwid"; http_uri; content:"Expect|3a 20|100-continue"; http_header; content:"filename=|22|"; fast_pattern; http_client_body; content:"Content-Type|3a 20|application/"; content:"|0d 0a 0d 0a|PK"; http_client_body; reference:md5,2fd68d384d80d53bcd63585c5a19ba98; classtype:trojan-activity; sid:20166320; rev:3; metadata:created_at 2020_04_09;)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement