ET MALWARE BPFDoor TCP Magic Packet (Inbound) M6
Query · suricata
flow:established,to_server;
dsize:24;
content:"|39 39 39 39|"; startswith; fast_pattern;
content:"|73|"; offset:10; depth:1;
pcre:"/^[a-z0-9_]{1,14}\x00*$/Ri";
flow:established,to_server;
dsize:24;
content:"|39 39 39 39|"; startswith; fast_pattern;
content:"|73|"; offset:10; depth:1;
pcre:"/^[a-z0-9_]{1,14}\x00*$/Ri";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.