""ET TROJAN Backdoor.Win32.Fynloski.A/DarkRat Checkin Outbound""

SID: 2013090

Revision: 8

Class Type: trojan-activity

Metadata: created_at 2010_11_22, updated_at 2012_09_27

Reference:

  • md5

  • a2f58a4215441276706f18519dae9102

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: to_server,established

Contents:

  • Value: "KEEPALIVE" Depth: 9

Within:

PCRE: "/^\x7c?\d/R"

Special Options:

source