ET MALWARE [Mandiant] UNC4841 SEASPY Backdoor Activity M2
Query · suricata
flow:stateless,to_server; flags:S; dsize:>9; content:"TfuZ"; startswith; threshold:type limit,track by_src,count 1,seconds 3600; target:dest_ip;
flow:stateless,to_server; flags:S; dsize:>9; content:"TfuZ"; startswith; threshold:type limit,track by_src,count 1,seconds 3600; target:dest_ip;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.