ET MALWARE PNScan.2 Inbound Status Check Response
Query · suricata
flow:established,from_server;
flowbits:isset,ET.PNScan.2;
http.header;
content:"Content-Length|3a 20|12|0d 0a|";
file.data;
content:"{|22|status|22 3a|1}"; fast_pattern;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.PNScan.2