[6120] 21/11/2018 -- 17:34:11 - (suricata.c:1085) (LogVersion) -- This is Suricata version 4.1.0-dev (rev 5aef72ef) [6120] 21/11/2018 -- 17:34:11 - (util-cpu.c:171) (UtilCpuPrintSummary) -- CPUs/cores online: 20 [6120] 21/11/2018 -- 17:34:11 - (util-luajit.c:98) (LuajitSetupStatesPool) -- luajit states preallocated: 128 [6120] 21/11/2018 -- 17:34:11 - (app-layer-htp.c:2310) (HTPConfigSetDefaultsPhase2) -- 'default' server has 'request-body-minimal-inspect-size' set to 33867 and 'request-body-inspect-window' set to 4092 after randomization. [6120] 21/11/2018 -- 17:34:11 - (app-layer-htp.c:2328) (HTPConfigSetDefaultsPhase2) -- 'default' server has 'response-body-minimal-inspect-size' set to 39285 and 'response-body-inspect-window' set to 15838 after randomization. [6120] 21/11/2018 -- 17:34:11 - (app-layer-smb-tcp-rust.c:295) (RegisterRustSMBTCPParsers) -- SMB stream depth: 0 [6120] 21/11/2018 -- 17:34:11 - (app-layer-modbus.c:1515) (RegisterModbusParsers) -- Protocol detection and parser disabled for modbus protocol. [6120] 21/11/2018 -- 17:34:11 - (app-layer-enip.c:416) (RegisterENIPUDPParsers) -- Protocol detection and parser disabled for enip protocol. [6120] 21/11/2018 -- 17:34:11 - (app-layer-dnp3.c:1599) (RegisterDNP3Parsers) -- Protocol detection and parser disabled for DNP3. [6120] 21/11/2018 -- 17:34:11 - (host.c:254) (HostInitConfig) -- allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 [6120] 21/11/2018 -- 17:34:11 - (host.c:277) (HostInitConfig) -- preallocated 1000 hosts of size 136 [6120] 21/11/2018 -- 17:34:11 - (host.c:279) (HostInitConfig) -- host memory usage: 398144 bytes, maximum: 33554432 [6120] 21/11/2018 -- 17:34:11 - (util-coredump-config.c:129) (CoredumpLoadConfig) -- Core dump size set to unlimited. [6120] 21/11/2018 -- 17:34:11 - (defrag-hash.c:248) (DefragInitConfig) -- allocated 3670016 bytes of memory for the defrag hash... 65536 buckets of size 56 [6120] 21/11/2018 -- 17:34:11 - (defrag-hash.c:273) (DefragInitConfig) -- preallocated 65535 defrag trackers of size 160 [6120] 21/11/2018 -- 17:34:11 - (defrag-hash.c:280) (DefragInitConfig) -- defrag memory usage: 14155616 bytes, maximum: 33554432 [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:399) (StreamTcpInitConfig) -- stream "prealloc-sessions": 375000 (per thread) [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:418) (StreamTcpInitConfig) -- stream "memcap": 15032385536 [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:424) (StreamTcpInitConfig) -- stream "midstream" session pickups: disabled [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:430) (StreamTcpInitConfig) -- stream "async-oneside": disabled [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:447) (StreamTcpInitConfig) -- stream "checksum-validation": disabled [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:475) (StreamTcpInitConfig) -- stream."inline": disabled [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:488) (StreamTcpInitConfig) -- stream "bypass": enabled [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:510) (StreamTcpInitConfig) -- stream "max-synack-queued": 5 [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:532) (StreamTcpInitConfig) -- stream.reassembly "memcap": 21474836480 [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:550) (StreamTcpInitConfig) -- stream.reassembly "depth": 1048576 [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:626) (StreamTcpInitConfig) -- stream.reassembly "toserver-chunk-size": 2617 [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:628) (StreamTcpInitConfig) -- stream.reassembly "toclient-chunk-size": 2592 [6120] 21/11/2018 -- 17:34:11 - (stream-tcp.c:640) (StreamTcpInitConfig) -- stream.reassembly.raw: enabled [6120] 21/11/2018 -- 17:34:11 - (stream-tcp-reassemble.c:373) (StreamTcpReassemblyConfig) -- stream.reassembly "segment-prealloc": 200000 [6120] 21/11/2018 -- 17:34:11 - (util-logopenfile.c:501) (SCConfLogOpenGeneric) -- fast output device (regular) initialized: fast.log [6120] 21/11/2018 -- 17:34:11 - (util-logopenfile.c:501) (SCConfLogOpenGeneric) -- eve-log output device (regular) initialized: eve.json [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'alert' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'http' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dns' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tls' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'files' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smtp' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'nfs' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'smb' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'tftp' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ikev2' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'krb5' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'dhcp' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'ssh' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'stats' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'flow' [6120] 21/11/2018 -- 17:34:11 - (runmodes.c:618) (RunModeInitializeEveOutput) -- enabling 'eve-log' module 'metadata' [6120] 21/11/2018 -- 17:34:11 - (util-logopenfile.c:501) (SCConfLogOpenGeneric) -- stats output device (regular) initialized: stats.log [6120] 21/11/2018 -- 17:34:11 - (suricata.c:2437) (SetupDelayedDetect) -- Delayed detect disabled [6120] 21/11/2018 -- 17:34:11 - (util-conf.c:115) (ConfUnixSocketIsEnable) -- Running in live mode, activating unix socket [6120] 21/11/2018 -- 17:34:11 - (detect-engine.c:1514) (DetectEngineCtxInitReal) -- pattern matchers: MPM: hs, SPM: hs [6120] 21/11/2018 -- 17:34:11 - (detect-engine.c:1915) (DetectEngineCtxLoadConf) -- grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 [6120] 21/11/2018 -- 17:34:11 - (detect-engine.c:1939) (DetectEngineCtxLoadConf) -- grouping: udp-whitelist (default) 53, 135, 5060 [6120] 21/11/2018 -- 17:34:11 - (detect-engine.c:1967) (DetectEngineCtxLoadConf) -- prefilter engines: MPM [6120] 21/11/2018 -- 17:34:11 - (reputation.c:609) (SRepInit) -- IP reputation disabled [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:247) (ProcessSigFiles) -- Loading rule file: /etc/suricata/rules/scirius.rules [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gozi C&C)"; tls_fingerprint:"2c:34:71:27:a7:33:33:09:51:af:90:bd:39:1d:4c:b2:5c:f6:86:20"; sid:902333297; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7456 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gozi C&C)"; tls_fingerprint:"5b:66:b1:0a:ec:a3:0b:93:d2:c7:76:c9:2b:3b:cb:02:d6:d3:6a:e5"; sid:902333299; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7460 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gozi C&C)"; tls_fingerprint:"7e:55:fb:87:67:15:0f:56:55:cd:0a:b8:53:c4:6c:cd:83:e0:e2:6c"; sid:902333301; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7462 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gootkit C&C)"; tls_fingerprint:"b1:5b:34:ca:a4:71:58:b1:7b:5d:64:fc:ce:46:21:19:35:5c:db:16"; sid:902333303; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7464 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gootkit C&C)"; tls_fingerprint:"5c:95:5d:b9:6e:be:42:de:ea:35:db:89:92:ca:f9:43:e2:a3:3d:b1"; sid:902333305; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7466 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gozi C&C)"; tls_fingerprint:"ac:d5:3a:9a:fe:1e:cc:f4:13:14:05:19:93:5d:ab:f7:52:b4:43:4b"; sid:902333307; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7468 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (IcedID C&C)"; tls_fingerprint:"ac:2d:7d:26:06:2d:68:bc:48:87:0c:fe:1a:fb:c1:dd:42:a2:43:41"; sid:902333309; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7470 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (IcedId C&C)"; tls_fingerprint:"d6:41:2d:b5:0d:f6:62:b5:af:43:a2:a2:0d:fe:58:e0:0c:ab:09:96"; sid:902333311; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7472 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (PandaZeuS C&C)"; tls_fingerprint:"a2:39:ed:1a:80:53:2b:74:1f:b9:e0:94:cd:51:b0:5c:ea:9b:6f:fa"; sid:902333313; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7474 [6120] 21/11/2018 -- 17:34:11 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:11 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gozi C&C)"; tls_fingerprint:"a9:03:28:dc:8d:f0:80:df:60:1e:67:3f:30:59:a7:03:c0:c4:06:84"; sid:902333315; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 7476 [6120] 21/11/2018 -- 17:34:14 - (detect-parse.c:631) (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(102)] - unknown rule keyword 'tls_fingerprint'. [6120] 21/11/2018 -- 17:34:14 - (detect-engine-loader.c:184) (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - error parsing signature "alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"SSL Fingerprint Blacklist: Malicious SSL certificate detected (Gozi C&C)"; tls_fingerprint:"38:83:e2:f7:30:57:40:57:d5:cd:f9:1e:ae:56:2b:9c:56:e5:b5:0d"; sid:902333295; rev:1;)" from file /etc/suricata/rules/scirius.rules at line 46806 [6120] 21/11/2018 -- 17:34:14 - (detect-engine-loader.c:351) (SigLoadSignatures) -- 1 rule files processed. 23740 rules successfully loaded, 11 rules failed [6120] 21/11/2018 -- 17:34:14 - (util-threshold-config.c:1126) (SCThresholdConfParseFile) -- Threshold config parsed: 23 rule(s) found [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:340) (SetupBuiltinMpm) -- using shared mpm ctx' for tcp-packet [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:340) (SetupBuiltinMpm) -- using shared mpm ctx' for tcp-stream [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:340) (SetupBuiltinMpm) -- using shared mpm ctx' for udp-packet [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:340) (SetupBuiltinMpm) -- using shared mpm ctx' for other-ip [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_uri [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_request_line [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_client_body [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_response_line [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header_names [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_header_names [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_accept [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_accept_enc [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_accept_lang [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_referer [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_connection [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_len [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_len [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_type [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_content_type [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_protocol [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_protocol [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_start [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_start [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_header [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_header [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_method [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_cookie [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_cookie [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_uri [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_user_agent [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_host [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_raw_host [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_stat_msg [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for http_stat_code [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dns_query [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls_sni [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls_cert_issuer [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls_cert_subject [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls_cert_serial [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for tls_cert_fingerprint [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ja3_hash [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ja3_string [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dce_stub_data [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for dce_stub_data [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for smb_named_pipe [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for smb_share [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_protocol [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_protocol [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_software [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for ssh_software [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for file_data [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for krb5_cname [6120] 21/11/2018 -- 17:34:14 - (detect-engine-mpm.c:285) (DetectMpmSetupAppMpms) -- using shared mpm ctx' for krb5_sname [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1427) (SigAddressPrepareStage1) -- 23745 signatures processed. 1033 are IP-only rules, 7158 are inspecting packet payload, 18222 inspect application layer, 0 are decoder event only [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1430) (SigAddressPrepareStage1) -- building signature grouping structure, stage 1: preprocessing rules... complete [6120] 21/11/2018 -- 17:34:14 - (detect-flowbits.c:480) (DetectFlowbitsAnalyze) -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'BSis.vnc.setup' is checked but not set. Checked in 2002914 and 3 other sigs [6120] 21/11/2018 -- 17:34:14 - (detect-flowbits.c:480) (DetectFlowbitsAnalyze) -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'BSvnc.null.auth.sent' is checked but not set. Checked in 2002917 and 0 other sigs [6120] 21/11/2018 -- 17:34:14 - (detect-flowbits.c:480) (DetectFlowbitsAnalyze) -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'BSvnc.auth.agreed' is checked but not set. Checked in 2002921 and 0 other sigs [6120] 21/11/2018 -- 17:34:14 - (detect-flowbits.c:480) (DetectFlowbitsAnalyze) -- [ERRCODE: SC_WARN_FLOWBIT(306)] - flowbit 'ET.Netwire.HB.1' is checked but not set. Checked in 2018282 and 0 other sigs [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1269) (RulesGroupByPorts) -- TCP toserver: 41 port groups, 36 unique SGH's, 5 copies [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1269) (RulesGroupByPorts) -- TCP toclient: 21 port groups, 21 unique SGH's, 0 copies [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1269) (RulesGroupByPorts) -- UDP toserver: 41 port groups, 36 unique SGH's, 5 copies [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1269) (RulesGroupByPorts) -- UDP toclient: 21 port groups, 15 unique SGH's, 6 copies [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1015) (RulesGroupByProto) -- OTHER toserver: 254 proto groups, 5 unique SGH's, 249 copies [6120] 21/11/2018 -- 17:34:14 - (detect-engine-build.c:1052) (RulesGroupByProto) -- OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies [6120] 21/11/2018 -- 17:34:15 - (detect-engine-build.c:1802) (SigAddressPrepareStage4) -- Unique rule groups: 113 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1000) (MpmStoreReportStats) -- Builtin MPM "toserver TCP packet": 31 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1000) (MpmStoreReportStats) -- Builtin MPM "toclient TCP packet": 19 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1000) (MpmStoreReportStats) -- Builtin MPM "toserver TCP stream": 31 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1000) (MpmStoreReportStats) -- Builtin MPM "toclient TCP stream": 21 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1000) (MpmStoreReportStats) -- Builtin MPM "toserver UDP packet": 36 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1000) (MpmStoreReportStats) -- Builtin MPM "toclient UDP packet": 14 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1000) (MpmStoreReportStats) -- Builtin MPM "other IP packet": 2 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_uri": 10 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_request_line": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_client_body": 6 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient http_response_line": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_header": 6 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient http_header": 3 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_header_names": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_accept": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_referer": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_content_len": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_content_type": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient http_content_type": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_start": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_raw_header": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient http_raw_header": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_method": 4 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_cookie": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient http_cookie": 2 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_raw_uri": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_user_agent": 4 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver http_host": 2 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient http_stat_code": 2 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver dns_query": 4 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver tls_sni": 2 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient tls_cert_issuer": 2 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient tls_cert_subject": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient tls_cert_serial": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver ssh_protocol": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toserver file_data": 1 [6120] 21/11/2018 -- 17:34:15 - (detect-engine-mpm.c:1007) (MpmStoreReportStats) -- AppLayer MPM "toclient file_data": 5 [6120] 21/11/2018 -- 17:34:20 - (runmode-af-packet.c:233) (ParseAFPConfig) -- Enabling tpacket v3 capture on iface enp179s0f1 [6120] 21/11/2018 -- 17:34:20 - (runmode-af-packet.c:328) (ParseAFPConfig) -- Using queue based cluster mode for AF_PACKET (iface enp179s0f1) [6120] 21/11/2018 -- 17:34:20 - (runmode-af-packet.c:401) (ParseAFPConfig) -- af-packet will use '/etc/suricata/ebpf/bypass_filter.bpf' as eBPF filter file [6120] 21/11/2018 -- 17:34:20 - (runmode-af-packet.c:408) (ParseAFPConfig) -- Using bypass kernel functionality for AF_PACKET (iface enp179s0f1) [6120] 21/11/2018 -- 17:34:20 - (runmode-af-packet.c:643) (ParseAFPConfig) -- enp179s0f1: enabling zero copy mode by using data release call [6120] 21/11/2018 -- 17:34:20 - (util-runmodes.c:297) (RunModeSetLiveCaptureWorkersForDevice) -- Going to use 20 thread(s) [6120] 21/11/2018 -- 17:34:22 - (flow-manager.c:819) (FlowManagerThreadSpawn) -- using 1 flow manager threads [6120] 21/11/2018 -- 17:34:22 - (flow-manager.c:980) (FlowRecyclerThreadSpawn) -- using 1 flow recycler threads [6120] 21/11/2018 -- 17:34:22 - (util-conf.c:115) (ConfUnixSocketIsEnable) -- Running in live mode, activating unix socket [6120] 21/11/2018 -- 17:34:22 - (unix-manager.c:131) (UnixNew) -- Using unix socket file '/var/run/suricata/suricata-command.socket' [6120] 21/11/2018 -- 17:34:22 - (tm-threads.c:2172) (TmThreadWaitOnThreadInit) -- all 20 packet processing threads, 5 management threads initialized, engine started. [6217] 21/11/2018 -- 17:34:22 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6217] 21/11/2018 -- 17:34:22 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6220] 21/11/2018 -- 17:34:22 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6220] 21/11/2018 -- 17:34:22 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6221] 21/11/2018 -- 17:34:22 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6221] 21/11/2018 -- 17:34:22 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6222] 21/11/2018 -- 17:34:22 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6222] 21/11/2018 -- 17:34:22 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6223] 21/11/2018 -- 17:34:22 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6223] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6224] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6224] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6225] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6225] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6226] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6226] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6227] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6227] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6228] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6228] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6234] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6234] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6235] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6235] 21/11/2018 -- 17:34:23 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6236] 21/11/2018 -- 17:34:23 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6236] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6237] 21/11/2018 -- 17:34:24 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6237] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6238] 21/11/2018 -- 17:34:24 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6238] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6239] 21/11/2018 -- 17:34:24 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6239] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6242] 21/11/2018 -- 17:34:24 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6242] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6247] 21/11/2018 -- 17:34:24 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6247] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6249] 21/11/2018 -- 17:34:24 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6249] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6250] 21/11/2018 -- 17:34:24 - (source-af-packet.c:1773) (AFPComputeRingParamsV3) -- AF_PACKET V3 RX Ring params: block_size=32768 block_nr=10001 frame_size=1600 frame_nr=200020 (mem: 327712768) [6250] 21/11/2018 -- 17:34:24 - (source-af-packet.c:2025) (SetEbpfFilter) -- Activated eBPF filter on socket [6250] 21/11/2018 -- 17:34:24 - (source-af-packet.c:513) (AFPPeersListReachedInc) -- All AFP capture threads are running.