SCAN [PTsecurity] Neutrino shell probing die(@md5(
Sourceptresearch/attackdetection
CreatedDecember 13, 2021
UpdatedDecember 13, 2021
Classificationattempted-recon
alert http any any -> any any (msg:"SCAN [PTsecurity] Neutrino shell probing die(@md5("; flow:established, to_server; content:"die(@md5("; isdataat:!20, relative; threshold:type limit, track by_src, seconds 300, count 1; reference:url, github.com/ptresearch/AttackDetection; classtype:attempted-recon; sid:10003765; rev:2;)
References
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!