ET MALWARE Nitrogen Loader Activity
Query · suricata
flow:established,to_server;
http.uri;
content:"/chat/"; startswith;
pcre:"/^[a-zA-Z0-9+=/]{10}/R";
http.cookie;
content:"password.log|3d|"; startswith; fast_pattern;
target:src_ip;
flow:established,to_server;
http.uri;
content:"/chat/"; startswith;
pcre:"/^[a-zA-Z0-9+=/]{10}/R";
http.cookie;
content:"password.log|3d|"; startswith; fast_pattern;
target:src_ip;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.