Hey folks, I've been hearing a lot of ruminations about a potential wave of ransomware/wiper malware wiping ESXi servers using CVE 2021-21974 - OpenSLP.
I managed to put together a signature for it, and I'm really fucking proud of how it all came together so fast. The rule will be out with tonight's ETOPEN rule release -- that means the rule will be available for snort 2.9.x, Suri4, and Suri5+