
Ankit Mehta
@SecvynIndiaTrusted contributorCompletionist
8 followers9,563 downloads9,509 copies160 likes52,104 views
8,664 detections
Filters
Last updated
All Time
Detection languages
5,836
1,081
677
439
436
Categories
2,649
2,042
1,307
947
815
Platforms
6,007
955
872
708
593
Products / Services
2,805
1,372
1,362
725
707
MITRE Techniques
2,089
2,045
1,444
1,090
1,083
CVEs
17
16
15
11
11
IDS Classtypes
250
132
95
68
64
IDS Protocols
405
140
49
36
14
This rule detects network connections to FTP servers (port 21) where the remote URL contains keywords associated with NetWare or Novell, along with suspicious whitespace patterns. This could indicate an attempt to exploit a known vulnerability related to whitespace handling in NetWare FTP servers, potentially the 'Squidbleed' vulnerability.
Open-source derived remote access trojan with plugin architecture
Clipboard hijacking malware for cryptocurrency address substitution
Open-source derived remote access trojan with plugin architecture
Clipboard hijacking malware for cryptocurrency address substitution
Commodity .NET keylogger and remote access trojan
Commodity .NET keylogger and remote access trojan
Commodity .NET keylogger and remote access trojan
Open-source derived remote access trojan with plugin architecture
Clipboard hijacking malware for cryptocurrency address substitution
