ET MALWARE [PTsecurity] Ursnif Encoded Payload Inbound
Query · suricata
flow:established,to_client; http.stat_code; content:"200"; file_data; content:"|3d fa 61 3c 79 ee de ea 18 90 08 95 55 44 8d 41|"; depth:16; fast_pattern;
flow:established,to_client; http.stat_code; content:"200"; file_data; content:"|3d fa 61 3c 79 ee de ea 18 90 08 95 55 44 8d 41|"; depth:16; fast_pattern;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.