Advertisement
James_inthe_box

RocketX snort suricata

Apr 9th, 2020
17,222
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.46 KB | None | 0 0
  1. alert tcp any any -> any $HTTP_PORTS (msg:"RocketX Infostealer"; flow:to_server,established; content:"POST"; http_method; content:"hwid"; http_uri; content:"Expect|3a 20|100-continue"; http_header; content:"filename=|22|"; fast_pattern; http_client_body; content:"Content-Type|3a 20|application/"; content:"|0d 0a 0d 0a|PK"; http_client_body; reference:md5,2fd68d384d80d53bcd63585c5a19ba98; classtype:trojan-activity; sid:20166320; rev:3; metadata:created_at 2020_04_09;)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement