На
https://rules.emergingthreats.net/open/suricata-4.0/rules/emerging-trojan.rules есть сигнатура:
alert tcp any any -> any any (msg:"ET TROJAN ELF/muBoT IRC Activity 4"; flow:established,from_server; content:"NOTICE"; content:"FLOOD <target> <port> <secs>"; fast_pattern; distance:0; reference:url,
pastebin.com/EH1SH9aL; classtype:trojan-activity; sid:2021915; rev:1; metadata:created_at 2015_10_06, updated_at 2015_10_06;)
те "NOTICE" + "FLOOD <target> <port> <secs>"
На
https://doc.emergingthreats.net/2021915 та же сигнатура (тот же сид) и там
alert tcp any any -> any any (msg:"ET TROJAN ELF/muBoT IRC Activity 4"; flow:established,from_server; content:"NOTICE"; content:"FLOOD "; fast_pattern; distance:0; reference:url,
pastebin.com/EH1SH9aL; classtype:trojan-activity; sid:2021915; rev:1; metadata:created_at 2015_10_06, updated_at 2015_10_06;)
те "NOTICE"+"FLOOD " те без "<target> <port> <secs>"
WUT?