""ET TROJAN Cybergate/Rebhip/Spyrat Backdoor Keepalive""

SID: 2017990

Revision: 12

Class Type: trojan-activity

Metadata: created_at 2011_04_09, updated_at 2015_11_04

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: any

Flow: from_server,established

Contents:

  • Value: "ping|7c|" Depth: 5

  • Value: !"|7c|"

Within: 1

PCRE:

Special Options:

source