ET MALWARE [ANY.RUN] Win32/Gh0stRat Activity
Query · suricata
flow:established,to_server; content:"|32 00 32 00 32 00 32 00 00 00|"; depth:25; fast_pattern; content:"|78 9c|"; distance:4; within:2; target:src_ip;
flow:established,to_server; content:"|32 00 32 00 32 00 32 00 00 00|"; depth:25; fast_pattern; content:"|78 9c|"; distance:4; within:2; target:src_ip;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.