Back to Rule

Rule History

SID: 2019171 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 2Sep 12, 2014, 12:00 PM

ET MALWARE DoS.Linux/Elknot.E Checkin

alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE DoS.Linux/Elknot.E Checkin"; flow:established,to_server; dsize:401; content:!"|00 00|"; depth:2; content:"|10 27 60 ea|Linux|20|"; offset:4; depth:64; reference:md5,9a2a00f4bba2f3e0b1211a1f0cb48896; classtype:command-and-control; sid:2019171; rev:2; metadata:created_at 2014_09_12, signature_severity Major, updated_at 2019_07_26;)

Sep 12, 2014, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 12, 2014, 12:00 PM

Sep 10, 2024, 1:01 PM

rules/emerging-malware.rules