ET MALWARE Win32/SocksTroy Session Initiation Attempt M1
Query · suricata
stream_size:client,<,263; flow:established,to_server; content:"|00 00 fe 00|"; offset:2; depth:4; byte_jump:4,0, little, from_beginning, post_offset 3; isdataat:!2,relative;
stream_size:client,<,263; flow:established,to_server; content:"|00 00 fe 00|"; offset:2; depth:4; byte_jump:4,0, little, from_beginning, post_offset 3; isdataat:!2,relative;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.