summaryrefslogtreecommitdiffstats
path: root/clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml
blob: 1cce7f79b311513002360401c23e1d0ef07c6f06 (plain)
1
2
3
4
5
6
7
8
9
sid: "10000003"
protocol: tcp
dest_port: any
dest_ip: $HOME_NET
src_port: any
src_ip: any
msg: MALWARE-CNC User-Agent ASafaWeb Scan
rev: "001"
content: '"asafaweb.com"'