Back to Rule

Rule History

SID: 2019172 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 4Aug 19, 2014, 12:00 PM

ET MALWARE Linux.DDoS Checkin

alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Linux.DDoS Checkin"; flow:established,to_server; dsize:1024; content:"VERSONEX|3a|"; depth:9; content:"|7c|Hacker|00 00 00|"; distance:0; reference:md5,0eab12cebbf1c8f25d82c65f34aab9d7; classtype:command-and-control; sid:2019172; rev:4; metadata:created_at 2014_08_19, signature_severity Major, updated_at 2019_07_26;)

Aug 19, 2014, 12:00 PM

Jul 26, 2019, 12:00 PM

Aug 19, 2014, 12:00 PM

Sep 10, 2024, 1:01 PM

rules/emerging-malware.rules