ET MALWARE Win32/Injector.ULH CnC Activity
Query · suricata
flow:established,to_server; http.start; content:"GET /swidget/d23r523t4id HTTP/1.1|0d 0a|Host|3a 20|whos.amung.us|0d 0a 0d 0a|"; bsize:58; fast_pattern;
flow:established,to_server; http.start; content:"GET /swidget/d23r523t4id HTTP/1.1|0d 0a|Host|3a 20|whos.amung.us|0d 0a 0d 0a|"; bsize:58; fast_pattern;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.