A systems administrator was given the following IOC to detect the presence of a malicious piece of software communicating with its command-and-control server:
POST /malicious.php -
User-Agent: Malicious Tool V 1.0
Host: www.malicious.com -
The IOC documentation suggests the URL is the only part that could change. Which of the following regular expressions would allow the systems administrator to determine if any of the company hosts are compromised, while reducing false positives?
ThatGuyOverThere
Highly Voted 1 year, 6 months agoOdinAtlasSteel
Highly Voted 1 year, 5 months agoSteel16
Most Recent 2 months agoSteel16
2 months agoSteel16
2 months ago1c7fe0b
3 months, 2 weeks ago3c12b86
4 months, 1 week agoBright07
4 months, 4 weeks agoCraZee
1 year, 3 months agob49eb27
1 year, 1 month agoweaponxcel
1 year, 6 months agoTrap_D0_r
1 year, 3 months agoCoinUmbrella
1 year, 7 months agoCXSSP
1 year, 7 months ago