""ET TROJAN MS Remote Desktop micros User Login Request""

SID: 2018124

Revision: 3

Class Type: protocol-command-decode

Metadata: created_at 2014_02_12, updated_at 2014_02_13

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: 3389

Flow: to_server,established

Contents:

  • Value: "|03 00 00|" Depth: 3

  • Value: "|e0 00 00 00 00 00|"

  • Value: "Cookie|3a| mstshash=micros|0d 0a|"

Within: 6

PCRE:

Special Options:

  • nocase

source