ET MALWARE MSIL/Spyware Activity via Telegram (Response)
Query · suricata
flowbits:isset,ET.generictelegram; flow:established,to_client; http.stat_code; content:"200"; http.content_type; content:"application/json"; bsize:16; file.data; content:"|7b 22 6f 6b 22 3a 74 72 75 65 2c 22 72 65 73 75 6c 74 22 3a 7b 22|"; startswith; fast_pattern; content:"|22 74 65 78 74 22 3a 22 54 68 69 73 20 4e 6f 74 20 52 44 50 22 7d 7d|"; endswith; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.generictelegram