ET MALWARE DNSBin Demo - Data Exfil
Query · suricata
threshold:type limit, track by_src, seconds 180, count 1; dns.query; bsize:>32; content:"|2e|"; content:".d.zhack.ca"; distance:20; within:11; endswith;
threshold:type limit, track by_src, seconds 180, count 1; dns.query; bsize:>32; content:"|2e|"; content:".d.zhack.ca"; distance:20; within:11; endswith;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.