ET MALWARE [ANY.RUN] Mekotio Banking Trojan TCP Request
Query · suricata
flow:established,to_server;
dsize:<30;
content:"pimbsbd"; startswith; fast_pattern;
pcre:"/^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\r\n/R";
target:src_ip;
flow:established,to_server;
dsize:<30;
content:"pimbsbd"; startswith; fast_pattern;
pcre:"/^\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\r\n/R";
target:src_ip;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.