ET MALWARE [PTsecurity] Gozi/Ursnif Payload v14
Query · suricata
flow:established,from_server; http.stat_code; content:"200"; file.data; content:"|d9 2c c6 af f6 26 56 bb 73 f5 c4 68 0f 90 d9 d4|"; depth:16; fast_pattern;
flow:established,from_server; http.stat_code; content:"200"; file.data; content:"|d9 2c c6 af f6 26 56 bb 73 f5 c4 68 0f 90 d9 d4|"; depth:16; fast_pattern;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.