ET ATTACK_RESPONSE MacSync Stealer Payload Inbound M1
Query · suricata
flow:established,to_client; http.response_body; content:"writeText|28 22|MacSync|20|Stealer|5c|n|5c|n|22 2c 20|writemind|20 26 20 22|info|22 29|"; target:dest_ip;
flow:established,to_client; http.response_body; content:"writeText|28 22|MacSync|20|Stealer|5c|n|5c|n|22 2c 20|writemind|20 26 20 22|info|22 29|"; target:dest_ip;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.