""ET TROJAN Mini/Cosmic Duke variant FTP upload""

SID: 2020158

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2015_01_08, updated_at 2015_01_08

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: 21

Flow: established,to_server

Contents:

  • Value: "STOR "

  • Value: ".bin|0d 0a|"

Within:

PCRE: "/^[A-F0-9]{48}.bin\r\n/R"

Special Options:

source