""ET TROJAN US-CERT TA14-353A Lightweight Backdoor 9""

SID: 2020015

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2014_12_23, updated_at 2014_12_23

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: any

Flow: established

Contents:

  • Value: "|8a 10 80 c2 4e 80 f2 79 88 10|"

  • Value: "|8a 10 80 f2 79 80 ea 4e 88 10|"

Within:

PCRE:

Special Options:

source