Back to Rule

Rule History

SID: 11001388 • Source: ptrules/open

Versions (6)

Version DetailsCurrent

Rev: 8Oct 9, 2025, 2:49 PM

BOTNET [PTsecurity] Tofsee Successful Connection FB set PT.Tofsee_1

alert tcp $EXTERNAL_NET !$HTTP_PORTS -> $HOME_NET any (msg: "BOTNET [PTsecurity] Tofsee Successful Connection FB set PT.Tofsee_1"; flow: established, to_client; dsize: 57; flags: PA; stream_size: client,<,200; stream_size: server,=,258; flowbits: isset, PT.Tofsee_0; flowbits: noalert; flowbits: unset, PT.Tofsee_0; flowbits: set, PT.Tofsee_1; reference: url, rules.ptsecurity.com; classtype: trojan-activity; sid: 11001388; rev: 8;)

Oct 9, 2025, 2:49 PM

Oct 9, 2025, 2:49 PM

Oct 16, 2025, 10:34 AM

Oct 16, 2025, 10:34 AM

rules/ptopen-malware.rules