ET MALWARE BPFDoor TCP Magic Packet (Inbound) M3
Query · suricata
flow:established,to_server;
dsize:24;
content:"|52 93 00 00|"; startswith; fast_pattern;
content:"|73|"; offset:10; depth:1;
pcre:"/^[a-z0-9_]{1,14}\x00*$/Ri";
flow:established,to_server;
dsize:24;
content:"|52 93 00 00|"; startswith; fast_pattern;
content:"|73|"; offset:10; depth:1;
pcre:"/^[a-z0-9_]{1,14}\x00*$/Ri";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.