SID: 2034504

Revision: 1

Class Type: bad-unknown

Metadata: created_at 2021_11_18, updated_at 2021_11_18

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: [$HOME_NET,$HTTP_SERVERS]

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "200"

  • Value: "|0d 0a|ps|20|aux"

  • Value: "kill|20|-9"

Within:

PCRE: "/^[^\r\n]+(?:mine.moneropool|xmr.crypto-pool|monerohash)[^\r\n]+kill\x20-9/R"

Special Options:

  • http_stat_code

  • file_data

  • fast_pattern

source