ET MALWARE ZeroAccess/Max++ Rootkit C&C Activity 1
Query · suricata
flow:established,to_server;
http.uri;
content:".php?w=";
content:"&i="; distance:0;
content:"&a="; distance:0;
pcre:"/\.php\?w=\d+&i=[0-9a-f]{32}&a=\d+$/";
flow:established,to_server;
http.uri;
content:".php?w=";
content:"&i="; distance:0;
content:"&a="; distance:0;
pcre:"/\.php\?w=\d+&i=[0-9a-f]{32}&a=\d+$/";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.