ET MALWARE Win32/Enchanim Process List Dump
Query · suricata
flow:to_server,established; http.method; content:"GET"; http.uri; content:"&pl=|5b|System|20|Process"; content:"svchost.exe"; content:"&r="; content:"&g="; content:"&s="; content:"&c=";
flow:to_server,established; http.method; content:"GET"; http.uri; content:"&pl=|5b|System|20|Process"; content:"svchost.exe"; content:"&r="; content:"&g="; content:"&s="; content:"&c=";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.