ET MALWARE Linux/Onimiki DNS trojan activity long format (Inbound)
Query · suricata
byte_test:1,!&,128,2;
content:"|00 01 00 00 00 00 00 00 38|"; offset:4; depth:9;
pcre:"/^[a-z0-9]{23}[a-f0-9]{33}.[a-z0-9\-_]+.[a-z0-9\-_]+\x00\x00\x01\x00\x01/Rsi";
byte_test:1,!&,128,2;
content:"|00 01 00 00 00 00 00 00 38|"; offset:4; depth:9;
pcre:"/^[a-z0-9]{23}[a-f0-9]{33}.[a-z0-9\-_]+.[a-z0-9\-_]+\x00\x00\x01\x00\x01/Rsi";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.