ET MALWARE Possible Inbound PowerShell via Invoke-PSImage Stego
Query · suricata
flow:established,to_client; file_data; content:"|89 50 4e 47|"; depth:8; content:"c2FsIGEgTmV3LU9iamVjdDt"; within:75; fast_pattern;
flow:established,to_client; file_data; content:"|89 50 4e 47|"; depth:8; content:"c2FsIGEgTmV3LU9iamVjdDt"; within:75; fast_pattern;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.