""ET TROJAN Possible Dyre SSL Cert Jan 22 2015""

SID: 2020289

Revision: 3

Class Type: trojan-activity

Metadata: attack_target Client_Endpoint, created_at 2015_01_23, deployment Perimeter, former_category CURRENT_EVENTS, signature_severity Major, tag SSL_Malicious_Cert, updated_at 2022_03_19

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: [443,4443]

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "|16|"

  • Value: "|0b|"

  • Value: "|09 00 92 87 8f 35 b4 aa 08 d1|"

  • Value: "|06 03 55 04 07|"

  • Value: "|06|Taipei"

Within: 7

PCRE:

Special Options:

  • fast_pattern

source