Commit 45cf6fa1 by mmorenog

Merge pull request #62 from DottoPing/patch-2

Update XOR_DDosv1
parents e1de6bbb 35d27f71
rule XOR_DDosv1 : DDoS rule XOR_DDosv1 : DDoS
{ {
meta: meta:
author = “Akamai SIRT” author = "Akamai SIRT"
description = “Rule to detect XOR DDos infection” description = "Rule to detect XOR DDos infection"
strings: strings:
$st0 = “BB2FA36AAA9541F0” $st0 = "BB2FA36AAA9541F0"
$st1 = “md5=” $st1 = "md5="
$st2 = “denyip=” $st2 = "denyip="
$st3 = “filename=” $st3 = "filename="
$st4 = “rmfile=” $st4 = "rmfile="
$st5 = “exec_packet” $st5 = "exec_packet"
$st6 = “build_iphdr” $st6 = "build_iphdr"
condition: condition:
all of them all of them
} }
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment