ROOTKIT [PTsecurity] Winnti
Sourceptrules/open
CreatedOctober 9, 2025
UpdatedOctober 9, 2025
Classificationtrojan-activity
alert tcp any any -> any any (msg:"ROOTKIT [PTsecurity] Winnti"; flow:established, to_server; content:"848923JNNWWAAV03"; depth:30; fast_pattern; reference:url, https://app.any.run/tasks/0e9aa891-01d3-42b4-aaea-63fa191a6dcb; reference:url, rules.ptsecurity.com; classtype:trojan-activity; sid:10011352; rev:1;)
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!