ET MALWARE Suspected fraud-bridge DNS Tunnel
Query · suricata
threshold:type both, track by_src, count 60, seconds 10;
dns.query;
content:"AAAA--.";
pcre:"/^[A-Za-z0-9\/\-\+]{10,}AAAA--\./s";
threshold:type both, track by_src, count 60, seconds 10;
dns.query;
content:"AAAA--.";
pcre:"/^[A-Za-z0-9\/\-\+]{10,}AAAA--\./s";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.