avatar

Ankit Mehta

@Secvyn
IndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views

8,664 detections

This rule detects network connections to FTP servers (port 21) where the remote URL contains keywords associated with NetWare or Novell, along with suspicious whitespace patterns. This could indicate an attempt to exploit a known vulnerability related to whitespace handling in NetWare FTP servers, potentially the 'Squidbleed' vulnerability.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
309
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Commodity .NET keylogger and remote access trojan
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Commodity .NET keylogger and remote access trojan
avatar
Ankit Mehta@Secvyn
Bharat Cyber Guardians
3 months ago
001
Commodity .NET keylogger and remote access trojan
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Open-source derived remote access trojan with plugin architecture
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001
Clipboard hijacking malware for cryptocurrency address substitution
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
3 months ago
001