""ET TROJAN US-CERT TA14-353A Lightweight Backdoor 10""

SID: 2020016

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2014_12_23, updated_at 2015_03_16

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: any

Flow: established

Contents:

  • Value: "Sleepy!@#qaz13402scvsde890"

  • Value: "BC435@PRO62384923412!@3!"

  • Value: !"content|3a 22|BC435@PRO62384923412!@3!|22 3b|"

Within:

PCRE:

Special Options:

  • nocase

source