James_inthe_box

Socks Loader sig

May 7th, 2019
516
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.27 KB | None | 0 0
  1. alert tcp any any -> any $HTTP_PORTS (msg:"Socks Loader Download"; flow:established,to_server; content:"|2f|socks|2f|api|2f|key|3f|"; http_uri; reference:md5,5d90c6fd2b937e3567ac05fc25fb72c9; classtype:trojan-activity; sid:20166294; rev:1; metadata:created_at 2019_05_07;)
Advertisement
Add Comment
Please, Sign In to add comment