ET MALWARE ReverseRAT Activity (POST) M4
Query · suricata
flow:established,to_server; http.method; content:"POST"; http.uri; content:"/h_tt_p"; fast_pattern; bsize:7; http.header_names; content:!"User-Agent"; content:!"Referer"; content:!"Accept";
flow:established,to_server; http.method; content:"POST"; http.uri; content:"/h_tt_p"; fast_pattern; bsize:7; http.header_names; content:!"User-Agent"; content:!"Referer"; content:!"Accept";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.