ET MALWARE Redline Stealer TCP CnC Activity
Query · suricata
flow:established,to_server; dsize:<60; content:"|00 01 00 01 02 02 21|net|2e|tcp|3a 2f 2f|"; startswith; fast_pattern; content:"|2f 03 08 0c|"; endswith;
flow:established,to_server; dsize:<60; content:"|00 01 00 01 02 02 21|net|2e|tcp|3a 2f 2f|"; startswith; fast_pattern; content:"|2f 03 08 0c|"; endswith;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.