ET MALWARE Win32/ScarCruf Payload Inbound
Query · suricata
flow:established,to_client; http.response_body; content:"|4d 53 43 46|"; startswith; content:"trap.bat"; fast_pattern; content:"check.bat"; content:"rdssvc32.dll"; content:"rdssvc64.dll";
flow:established,to_client; http.response_body; content:"|4d 53 43 46|"; startswith; content:"trap.bat"; fast_pattern; content:"check.bat"; content:"rdssvc32.dll"; content:"rdssvc64.dll";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.